Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Research
Data sources: ZENODO
addClaim

Zero-Retention Print Relays: A Mere-Conduit Architecture for Time-Bound Document Reproduction under India's DPDPA 2023

Authors: Pulla, Abhinay Gokul;

Zero-Retention Print Relays: A Mere-Conduit Architecture for Time-Bound Document Reproduction under India's DPDPA 2023

Abstract

Neighbourhood print shops across India routinely receive identity documents, bank statements, medical records, and legal filings through consumer messaging applications. Those applications are archives: files persist on staff devices and in chat backups long after the paper has been handed to the customer. This report names that mismatch as a category error—using an archive tool to perform a relay job—and describes a production print-relay architecture, Docshy, that treats a print job as a short-lived encrypted conduit rather than a document store. In the deployed system (docshy.com, Google Cloud region asia-south1 / Mumbai), the customer encrypts the file in the browser with AES-256-GCM before upload. The upload is bound to a shop by a static HMAC-authenticated counter QR. The platform unwraps the client layer once at ingest in order to validate file type, then re-envelopes the payload with a per-object data encryption key wrapped by Google Cloud KMS and stores ciphertext in Cloud Storage. Authenticated shop owners decrypt only at print time. On print confirmation the platform deletes the object and associated job metadata; a scheduled sweep removes aged leftovers. The report is explicit about non-goals: this is not zero-knowledge cryptography, not a regulator-issued DPDPA certificate, and not a claim that the shop screen or the printed page are invisible. The design target is zero retention of the product object on the relay after the print purpose ends.

Powered by OpenAIRE graph
Found an issue? Give us feedback