Blockchain-Based Zero-Knowledge Framework for Verifiable and Confidential File Sharing: Integrating NaCl Box Encryption with a Hyperledger Notary
Abstract
The increasing cases of data breaches, data tampering and information loss have posed an immediate demand to secure file sharing systems that guarantee privacy and verifiable integrity. The paper presents an end-to-end (E2E), encrypted file-sharing system based on the combination of client-side encryption and privately hosted, blockchain-based, notary service. All the encryption is done locally with the aid of the Networking and Cryptographic Library (NaCl) box primitive, and only the approved recipients are allowed access to the shared files with valid credentials. A lightweight local backend stores the encrypted data (ciphertext) and operates with public keys and user metadata; however, it does not access plaintext files and cannot decrypt them, keeping the entire data confidential. In order to offer non-repudiation, a hash of every encrypted file is computed with the Secure Hash Algorithm (SHA-256) and the result is stored in a private Hyperledger Fabric network. This provides an audit trail that can never be changed or tampered with and will not reveal the true files or encryption keys. In our prototype, sending to the blockchain ledger creates latency on an order of seconds 2.3 seconds in a 2.35-second total file-send path and file integrity verification by hash requires an average of 183 milliseconds. The suggested architecture is a good way to ensure confidentiality, proof of authenticity and integrity, and is a convenient way to provide the organization with a requirement to exchange files privately.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.