Cebit 2018: Legal Informatics Experts Develop Secure Data Spaces for Lawyers and SMEs
The exchange of information between lawyers and clients is protected by law. Whenever unencrypted e-mails are sent, however, this protection is undermined. And even with encryption in place, it is still possible to draw conclusions about who is communicating with whom, which should also be confidential, of course. Christoph Sorge, Juris Endowed Professor for Legal Informatics at the Saarland University, has been examining the matter. His team recently developed a web-based software system that protects the communication of lawyers and enterprises from third parties.
The Saarbrücken researchers will be presenting their software, “Mavora”, at the computer fair Cebit, taking place in Hannover from June 11 to 15 (Hall 27, Stand G75).
The fact that information technology can easily undermine the obligation of confidentiality is not new as such. Christoph Sorge, Professor of Legal Informatics at Saarland University, already recognized the deficit for law companies in 2016 and documented the issue for further research. “Although secure electronic communication systems have been around for a long time, they are hardly ever used in the legal context,” Sorge said at the time. In the same year, he founded the SOLE Software GmbH, together with attorney Stephan Ory and Dominik Leibenger, thus offering a technical solution for secure, but also user-friendly communications with clients.
The legal profession is observing the current development of the software system “Mavora” with particular interest. “The demand for accessible systems has increased significantly, especially after the German Federal Bar Association’s communication system, an electronic mailbox for attorneys (beA), had to be shut down preliminary because of its security deficiencies,“ says Dominik Leibenger, who is completing his doctoral thesis on the security of online storage and server services at Saarland University.
The Saarbrücken legal informatics team’s system is similar to a dead letterbox, which only the sender and the recipient know about. Within the Mavora software system, these mailboxes are secure online file folders that only can be accessed by the lawyer and the client, and whose content is additionally protected with end-to-end encryption. Therefore not even the provider of the online platform where Mavora is running is able to read the documents and messages uploaded to the platform. To share files with clients, lawyers simply have to set up their personal Mavora letterbox in their office, and then send their clients the according access data on a secure way. Clients receive their password securely by mail, fax or SMS, and can then log in to read messages and documents.
So even if attackers gained access to the entire database, they wouldn’t be able to read documents or even assign individual encrypted documents to specific clients. Metadata is also stored purely in encrypted form, whenever technically possible. Only notification e-mails, if users require them, have to be in unencrypted form temporarily. But it is also possible to do without these notifications.
Just as important is the fact that both lawyers and clients can handle the system with minimal effort. This is made possible by a sophisticated exchange system for the cryptographic codes, which are swapped automatically in the background.
And the founders are aiming for much more with their software project. They are currently working on adapting the system so that tax consultants and SMEs can also use these secure data rooms from Saarbrücken.
Institute for Legal Informatics at Saarland University
Saarland Informatics Campus
Phone: +49 681 302 5127
Professor Christoph Sorge
Endowed Professor for Legal Informatics
Saarland Informatics Campus