An administrator logs in with Smart ID Mobile App (Personal Mobile) to the Nexus GO Signing Portal, uploads a pdf document, invites persons to sign, and selects the required signing method for each person. An email is sent to each person.
Each signer follows the link in the email to the Nexus GO Signing Portal, and signs the document with the required method. For each signer, the following steps take place in Nexus GO:
A one-time RSA key pair is created.
The signer is associated to the key pair with two-factor authentication.
A hash of the PDF document is generated and signed with the private key of the key pair. The private key is then discarded.
The identity of the signer is securely bound to the key pair in a certificate, issued by the CA of the service, through the use of an HSM.
The signed document hash, the newly generated certificate, and a time stamp is built into the PDF file.