Ahmed Akhtar, Masoud Barati, Basit Shafiq, Omer Rana · 7 authors
The use of blockchain technology has been proposed to provide auditable access control for individual resources. Unlike the case where all resources are owned by a single organization, this work focuses on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may have event-driven constraints and can be overlapping in terms of the component conditions/rules as well as events. Existing work cannot handle event-driven constraints and does not sufficiently account for overlaps leading to significant overhead in terms of cost and computation time for evaluating authorizations over the blockchain. In this work, we propose an automata-theoretic approach for generating a cost-efficient composite access control policy. We reduce this composite policy generation problem to the standard weighted set cover problem. We show that the composite policy correctly captures all the local access control policies and reduces the policy evaluation cost over the blockchain. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and empirically validated the effectiveness and efficiency of our approach. Ablation studies were conducted to determine the impact of changes in individual service policies on the overall cost.
The increasing complexity of identity verification in U.S. banking and fintech ecosystems has highlighted thelimitations of traditional centralized Know Your Customer (KYC) processes, which often involve redundantdata collection, slow onboarding, and increased risk of data breaches. This study explores the design andimplementation of a Decentralized Identity (DID) architecture to enable secure, privacy-preserving, and usercentric KYC. By leveraging self-sovereign identity (SSI) principles, verifiable credentials (VCs), andcryptographic proofs, the proposed framework allows individuals to control their identity data while banks,fintechs, and regulatory authorities can authenticate users efficiently and compliantly. The architectureintegrates permissioned networks, identity wallets, credential issuers, and verifier nodes, supportinginteroperability with existing financial systems. Security, privacy, and regulatory compliance—including AML,FinCEN, and OFAC requirements—are embedded through robust cryptography, zero-knowledge proofs, andselective disclosure mechanisms. The study concludes that DID-enabled KYC can streamline onboarding,reduce operational costs, enhance user privacy, and strengthen overall financial ecosystem trust, providing aviable path for next-generation identity verification in U.S. banking and fintech.
The technological advancements in the field of E-healthcare have resulted in unprecedented generation of medical data which increases the risk of data security and privacy. Ensuring the privacy of Electronic Health Records (EHR) has become challenging due to outsourcing of healthcare information in the cloud. This increases the chance of data leakage to unauthorized users and affects the privacy and integrity of the user data. It requires a trustworthy central authority to protect the sensitive patient information from both internal and external attacks. This paper presents a blockchain based privacy preservation framework for securing EHR data. The proposed framework integrates the immutability and decentralized nature of blockchain with advanced cryptographic techniques to ensure the confidentiality, integrity and availability of EHR. The EHR data are stored in an InterPlanetary File System (IPFS) which is encrypted using a hybrid cryptographic algorithm. In addition, a novel smart contact based patient-centric access control is designed in this paper using a blockchain-based SHA-256 hashing algorithm to protect the privacy of patient data. The experimental results show that the proposed framework enables secure sharing of health information between network users with improved data privacy and security. Furthermore, the optimized search process reduces the time and space complexity compared to the traditional search process. Through the utilization of smart contracts, this framework enforces patient-centric access controls and allows patients to manage and authorize access to their medical data.
Identity Management Systems (IMS) manage individual profiles, user authorization, authentication, and access privileges. Paper-based profiles and defacement are vulnerable to spoofing, loss, and theft. Digital platforms with efficient IMS boost administrative processes and bring transparency and interoperability among establishments. The traditional paper-based identity systems are slow and rigid. Conventional centralized IMS lack transparency and are vulnerable to single-point failure. This paper presents a blockchain-aware decentralized identity management and access control (BADIMAC) model that mitigates these barriers. BADIMAC allows users to keep their digital identity within their control (i.e., self-sovereign identity). On the other hand, with the help of BADIMAC, service providers across enterprise boundaries can verify their identity without depending on any central authority. BADIMAC offers transparency and better security. The decentralized consensus-based design of BADIMAC enables the verifier to validate claims and establish proof of digital identity with process effectiveness.
Andrea Flamini, Giada Sciarretta, Mario Scuro, Amir Sharif · 6 authors
Verifiable credentials are a digital analogue of physical credentials. Their authenticity and integrity are protected by means of cryptographic techniques, and they can be presented to verifiers to reveal attributes or even predicates about the attributes included in the credential. One way to preserve privacy during presentation consists in selectively disclosing the attributes in a credential. In this paper we present the most widespread cryptographic mechanisms used to enable selective disclosure of attributes identifying two categories: the ones based on hiding commitments - e.g., mdl ISO/IEC 18013-5 - and the ones based on non-interactive zero-knowledge proofs - e.g., BBS signatures. We also include a description of the cryptographic primitives used to design such cryptographic mechanisms. We describe the design of the cryptographic mechanisms and compare them by performing an analysis on their standard maturity in terms of standardization, cryptographic agility and quantum safety, then we compare the features that they support with main focus on the unlinkability of presentations, the ability to create predicate proofs and support for threshold credential issuance. Finally we perform an experimental evaluation based on the Rust open source implementations that we have considered most relevant. In particular we evaluate the size of credentials and presentations built using different cryptographic mechanisms and the time needed to generate and verify them. We also highlight some trade-offs that must be considered in the instantiation of the cryptographic mechanisms.
The evolving landscape of Decentralized Finance (DeFi) has raised critical security concerns, especially pertaining to Protocols for Loanable Funds (PLFs) and their dependency on price oracles, which are susceptible to manipulation. The emergence of flash loans has further amplified these risks, enabling increasingly complex oracle manipulation attacks that can lead to significant financial losses. Responding to this threat, we first dissect the attack mechanism by formalizing the standard operational and adversary models for PLFs. Based on our analysis, we propose SecPLF, a robust and practical solution designed to counteract oracle manipulation attacks efficiently. SecPLF operates by tracking a price state for each crypto-asset, including the recent price and the timestamp of its last update. By imposing price constraints on the price oracle usage, SecPLF ensures a PLF only engages a price oracle if the last recorded price falls within a defined threshold, thereby negating the profitability of potential attacks. Our evaluation based on historical market data confirms SecPLF's efficacy in providing high-confidence prevention against arbitrage attacks that arise due to minor price differences. SecPLF delivers proactive protection against oracle manipulation attacks, offering ease of implementation, oracle-agnostic property, and resource and cost efficiency.
Christian Delgado‐von‐Eitzen, Luis Anido, Manuel J. Fernández Iglesias
The issuance and verification of academic certificates face significant challenges in the digital era. The proliferation of counterfeit credentials and the lack of a reliable, universally accepted system for issuing and validating them pose critical issues in the educational domain. Certificates, traditionally issued by centralized educational institutions using their proprietary systems, pose challenges for straightforward verification, generating uncertainty about the credibility of academic achievements. In addition to diplomas issued by academic entities, it is now necessary in virtually all professional fields to stay updated and obtain accreditation for certain skills or experiences, which is a determining factor in securing or enhancing employment. Yet, there is no platform available to consistently demonstrate these capabilities and experiences. This article introduces a novel model for issuing and verifying academic information using non-fungible tokens (NFTs) supported by blockchain technologies, focused on compliance with the General Data Protection Regulation (GDPR). It describes a model that grants control to the data subject, enabling the management of information access while adhering to key GDPR principles. Simultaneously, it remains compatible with existing systems within organizations, and is flexible in certifying various types of academic information. The implications of this model are discussed, emphasizing the importance of addressing privacy in blockchain-based applications.
As the e-commerce industry continues to grow, the challenges around warranty issuing and its management have become more significant. This research paper presents a software implementation of a blockchain-based e-commerce warranty system that utilizes non-fungible tokens (NFTs) to simplify the warranty management process for both consumers and manufacturers. Its features include automatic warranty issuing, verification, transfer of ownership, and warranty expiration. The system was made available as a service and was integrated into an existing e-commerce website clone to evaluate the ease of use. Additionally, a page listing all warranty NFTs owned by a user, irrespective of the e-commerce site of purchase, was created and linked to the original e-commerce website. As a result, the implemented system simplified the manufacturer/seller’s overhead of issuing and managing warranties and improved the user experience for consumers by showing all warranties owned by them in one place. This study illustrates the potential of public blockchains in the e-commerce sector, which has important implications for the use of blockchain-based warranty management systems. Received: 15 November 2023 | Revised: 26 December 2023 | Accepted: 3 January 2024 Conflicts of Interest The authors declare that they have no conflicts of interest to this work. Data Availability Statement Data sharing is not applicable to this article as no new data were created or analyzed in this study.
Abstract As a secure distributed ledger technology, blockchain has attracted widespread attention from academia and industry for its decentralization, immutability, and traceability characteristics. This paper proposes a cloud storage key security management scheme based on blockchain. To resist brute-force attacks launched by adversaries on ciphertexts, the scheme uses an oblivious pseudo-random function (OPRF) to generate randomized convergent keys and improve data confidentiality. Second, the scheme enhances the reliability of concurrent key management through a secret sharing mechanism, where convergent keys are split into key fragments and distributed on blockchain for storage. Even if a certain number of key fragments are lost or damaged, users can still recover complete key information through block transaction records. In addition, the scheme effectively supports file-level and block-level data security deduplication. Security analysis and experimental performance evaluation indicate that this scheme can ensure the security of keys and the confidentiality of data, and it has a low computational overhead for generating file-level encryption keys under this scheme. Even for a 100 MB file, the computational overhead required for generating encryption keys is less than 2 s, which improves computational efficiency.
Today, the healthcare sector is suffering from multiple security vulnerabilities that make it vulnerable to various types of cyberattacks. Therefore, robust security solutions need to be implemented in order to resolve these vulnerabilities. In this context, blockchain technology has emerged as a promising solution in several sectors, including the healthcare sector. It ensures enhanced security and greater transparency. It also boosts patient confidence and optimizes operational efficiency. In this paper, we first present an overview of the main classic healthcare applications: medical records management, traceability of medicines, and research and clinical trials. We then present a detailed analysis of the critical security vulnerabilities threatening these applications. Afterwards, we explain how blockchain technology can help to address these vulnerabilities. Finally, we discuss the various possible methods that aim to prevent traditional blockchain-related attacks in these healthcare applications and how blockchain technology is impacting and transforming the healthcare sector.
The concept of smart contracts (SCs) is becoming more prevalent, and their application is gaining traction across many diverse scenarios. However, producing poorly constructed contracts carries significant risks, including the potential for substantial financial loss, a lack of trust in the technology, and the risk of exposure to cyber-attacks. Several tools exist to assist in developing SCs, but their limited functionality increases development complexity. Expert knowledge is required to ensure contract reliability, resilience, and scalability. To overcome these risks and challenges, tools and services based on modeling and formal techniques are required that offer a robust methodology for SC verification and life-cycle management. This study proposes an engineering framework for the generation of a robust and verifiable smart contract (GRV-SC) framework that covers the entire SC life-cycle from design to deployment stages. It adopts SC modeling and automated formal verification methodologies to detect security vulnerabilities and improve resilience, extensibility, and code optimization to mitigate risks associated with SC development. Initially, the framework includes the implementation of a formal approach, using colored Petri nets (CPNs), to model cross-platform Digital Asset Modeling Language (DAML) SCs. It also incorporates a specialized type safety dynamic verifier, which is designed to detect and address new vulnerabilities that can arise in DAML contracts, such as access control and insecure direct object reference (Idor) vulnerabilities. The proposed GRV-SC framework provides a holistic approach to SC life-cycle management and aims to enhance the security, reliability, and adoption of SCs.
Mohd Najwadi Yusoff, Shams Mhmood Abd Ali, Hasan Falah Hasan
Blockchain technology has presented a promisingdecentralized paradigm to precludetrusted third parties' dominancy. It is a transparent and distributed ledger initially designed for digital cryptocurrencies while currently extended to servevarious industries. However, Blockchain immutability presents challenges, as it can be misused for storing illicit content, violating privacy regulations,and limiting data management flexibility. Policy Based Chameleon Hash Function (PBCH) has transformed blockchain rewriting contents concept via permitting modifiers to amend certain transaction since they possessed fundamental privileges satisfying certain access policy. However, PBCHFsuffers from efficiency issues due to its relianceon Chameleon Hash ephemeral Trapdoor (CHET) and Attribute-Based Encryption (ABE), significantly impacting overall efficiency. We propose the Efficient Policy-Based Chameleon (EPBCHF) construction by replacing CHET with Chameleon-Hashes by Dual Long-Term Trapdoors (CHDLTT) to address these challenges.Additionally, we introduce an enhanced encryption scheme resilient against chosen-ciphertext attacks (CCA) without compromising overall efficiency. Modelling EPBCHF proves practical instantiation accompanied by rigorous security proofs. Our construction provides a fine-grained redactable blockchain in comparison to the currently proposed solutions.The evaluated results confirm that the proposed EPBCHF is scalable and efficient due to having the ability to handle unlimited transaction volumes additionally, data is efficiently processed without further overhead meanwhile data size consistency reflects a robust memory management due to predicted memory size, network bandwidth and storage requirement for future growth thereby, EPBCHF is proven to be reliable and scalable.
NuLink provides privacy-preserving technology for decentralized applications via APIs. Users can securely store its valuable data, trade with others and so on. To ensure the privacy and security of service provided by NuLink, (zero-knowledge) proof systems are necessary. Zero-knowledge proof systems allow the prover to make the verifier believe that a certain conclusion is correct without providing any useful information to the verifier. In NuLink, we are going to use (zero-knowledge) proof system in the following three methods: 1. Users store their data through NuLink in a decentralized manner. To ensure that the storage clients are indeed storing the data, we employ proof of storage systems. In this system, users prepare certain challenges that can only be correctly answered by those who are actually storing the data. 2. Users have the option to outsource computations to NuLink. To verify the correctness of the computation results provided by the compute node, we require the node to provide a proof of correctness via SNARK systems. When sensitive parameters are used as inputs for computation, we utilize zk-SNARKs to prevent any potential leakage of these parameters. 3. Users may choose to trade their data through NuLink. To confirm that the buyer has sufficient digital funds and the seller possesses the desired data, both parties can provide a proof via zk-SNARKs. This builds confidence and prevents cheating during transactions. Using zero-knowledge proof systems, we can ensure that all nodes in NuLink behaves honestly and avoid cheating in the whole system.
Fatemeh Stodt, Mohammed B. Alshawki, Christoph Reich, Fabrice Théoleyre · 5 authors
In the rapidly evolving realm of the Industrial Internet of Things (IIoT), securing shop floor operations, especially in audit processes, is of critical importance. This paper confronts the challenge of ensuring data integrity and trust in IIoT systems by leveraging the capabilities of blockchain technology. The unique characteristics of blockchain, such as its immutable and decentralized ledger, establish a solid and transparent foundation for verifying shop floor transactions and activities. We introduce a privacy-centric approach, meticulously designed to comply with stringent data privacy regulations. This method allows auditors to authenticate both IIoT data and devices, ensuring confidentiality and adhering to regulatory standards. Our practical implementation strategy, tailored for shop floor environments, not only enhances the security of device and data integrity but also showcases robustness against specific adversarial threats, including network intrusion, data tampering, and unauthorized access. The findings indicate that our approach not only amplifies security protocols but also integrates effortlessly with existing IIoT infrastructures. It presents an efficient, scalable solution that elevates the safety and reliability of IIoT ecosystems, making it a significant step forward in the quest for secure and compliant industrial operations.
Advancements in technology have exposed significant vulnerabilities in academic credentialing systems; they are costly, time-consuming, and susceptible to sophisticated forms of fraud.This research proposes an innovative solution that can be implemented to make an almost complete overhaul of the traditional methods used to verify educational documents much faster, more secure, and more credible.In contrast to popular approaches that involve manual checks or third-party services, we propose a solution based on decentralized and immutable ledger tech.Similar attempts have been made before, such as the Blockers tool and Educt system, and although adequate, they need to catch up in the grand scheme of a more refined concept and interface.Our system goes further than these constraints because it uses QR codes for direct verification and a user-focused approach.A quantitative analysis utilizing Kaggle for secondary data demonstrates significant improvements: Our prototype significantly enhanced performance metrics compared to existing systems.Specifically, it facilitated a 30% increase in interactions per minute, providing a baseline of interactions from previous systems for more precise comparison.Additionally, user satisfaction improved markedly, with the prototype achieving a 40% increase in the proportion of users reporting high satisfaction, based on comparative satisfaction rates from conventional systems.By integrating the use of the prototype, improved security and organizational performance were seen, and students, teachers, and employers' feedback showed high satisfaction due to the usability and effectiveness of the developed system.It has been observed that the blockchain system is handy in this regard as it can easily connect and interoperate with the existing education systems while providing pseudonymity and scalability without compromising security.Future developments of the software include the new directions of its application in the further expansion of the guidance section, the enhancement of compatibility issues, and regular safety scan checks.
As the modern computing market experiences a surge in demand for efficient data-management solutions, challenges posed by centralized storage systems become more pronounced, especially with the proliferation of Internet of Things devices. Centralized storage, although cost-effective, faces issues of scalability, performance bottlenecks, and security vulnerabilities. With decentralized storage, data are distributed across nodes, offering redundancy, data availability, and enhanced security. Unfortunately, decentralized storage introduces its own challenges, such as complex data retrieval processes, potential inconsistencies in data versions, and difficulties in ensuring data privacy and integrity in a distributed setup. Effectively managing these challenges calls for innovative techniques. In response, this paper introduces a decentralized storage system that melds cloud-native concepts with blockchain technology. The proposed design delivers enhanced scalability, data security, and privacy. When operating on a containerized edge infrastructure, this storage system provides higher data-transfer speeds than the interplanetary file system. This research thus blends the advantages of cloud-native frameworks with the security mechanisms of blockchain, crafting a storage system that addresses the present-day challenges of data management in decentralized settings.
The rapid development of the metaverse and generative Artificial Intelligence (GAI) has led to the emergence of AI-Generated Content (AIGC). Unlike real-world products, AIGCs are represented as digital files, thus vulnerable to plagiarism and leakage on the Internet. In addition, the trading of AIGCs in the virtual world is prone to various trust issues between the involved participants. For example, some customers may try to avoid the payment after receiving the desired AIGC products, or the content sellers refuse to grant the products after obtaining the license fee. Existing digital asset management (DAM) systems often rely on a trusted third-party authority to mitigate these issues. However, this might lead to centralization problems such as the single-point-of-failure (SPoF) when the third parties are under attacks or being malicious. In this paper, we propose MetaTrade, a blockchain-empowered DAM framework that is designed to tackle these urgent trust issues, offering secured AIGC trading and management in the trustless metaverse environment. MetaTrade eliminates the role of the trusted third party, without requiring trust assumptions among participants. Numerical results show that MetaTrade offers higher performance and lower trading cost compared to existing platforms, while security analysis reveals that the framework is resilient against plagiarism, SPoF, and trust-related attacks. To showcase the feasibility of the design, a decentralized application (DApp) has been built on top of MetaTrade as a marketplace for metaverse AIGCs.
Cloud computing has emerged as a viable alternative to traditional computing infrastructures, offering various benefits. However, the adoption of cloud storage poses significant risks to data secrecy and integrity. This article presents an effective mechanism to preserve the secrecy and integrity of data stored on the public cloud by leveraging blockchain technology, smart contracts, and cryptographic primitives. The proposed approach utilizes a Solidity-based smart contract as an auditor for maintaining and verifying the integrity of outsourced data. To preserve data secrecy, symmetric encryption systems are employed to encrypt user data before outsourcing it. An extensive performance analysis is conducted to illustrate the efficiency of the proposed mechanism. Additionally, a rigorous assessment is conducted to ensure that the developed smart contract is free from vulnerabilities and to measure its associated running costs. The security analysis of the proposed system confirms that our approach can securely maintain the confidentiality and integrity of cloud storage, even in the presence of malicious entities. The proposed mechanism contributes to enhancing data security in cloud computing environments and can be used as a foundation for developing more secure cloud storage systems.
<div xmlns="http://www.tei-c.org/ns/1.0"> This study delves into the intersection of emerging technologies, focusing on the integration of blockchain to enhance security in data warehousing. Blockchain, with its decentralized and immutable ledger, offers a transformative solution to address critical security challenges in traditional data warehousing systems. The research explores the fundamentals of blockchain technology, including its distributed ledger, smart contracts, and cryptographic techniques, providing a comprehensive understanding of its applicability in fortifying data security. The paper examines real-world case studies, showcasing successful implementations of blockchain in diverse industries, such as supply chain management and healthcare. These cases highlight the tangible benefits of blockchain, including increased security, enhanced privacy, improved data integrity, and decentralized control. However, the study acknowledges challenges and considerations, such as scalability issues, integration complexities, regulatory compliance, and environmental concerns. It emphasizes the importance of careful planning and collaboration to overcome these challenges and successfully integrate blockchain into existing data warehousing systems. Looking to the future, the research discusses potential trends and developments in blockchain technologies, envisioning a global data collaboration, tokenization of data, and seamless integration with artificial intelligence and machine learning. The study concludes with a call to action for organizations to consider the adoption of blockchain for improved data security, offering a glimpse into the transformative potential of emerging technologies in shaping the future of data warehousing. </div>
This work proposes an end-to-end architecture for secure data federation and privacy-preserving analytics across multi-tenant cloud environments using homomorphic encryption (HE). We address the core challenge of enabling cross-tenant joins, aggregations, and model scoring without exposing plaintext or weakening tenant isolation. The framework integrates schema-level federation with encrypted data lakes, columnar ciphertext packing for vectorized operations, and an adaptive HE planner that selects between CKKS for approximate analytics and BFV/BGV for exact computations. To bound latency while maintaining correctness, we apply batching, ciphertext relinearization, and rotation scheduling, and offload heavy primitives to accelerator-ready microservices. Policy-aware orchestration enforces per-tenant keys via cloud KMS and supports fine-grained access control and revocation. For sensitive workflows, we compose HE with complementary protections secure enclaves for control-plane logic, differential privacy on result releases, and zero-knowledge proofs to attest query policy compliance achieving defense-in-depth without collapsing the HE trust model. The system exposes SQL-like and DataFrame APIs, a query optimizer that estimates noise budgets and bootstrapping costs, and lineage-rich audit trails for regulatory reporting. We outline deployment patterns on containerized clusters, discuss cost/performance trade-offs under realistic workloads, and provide guidance on tenancy hardening (noisy neighbor resistance, side-channel hygiene). The result is a practical pathway for organizations to collaborate on analytics and machine learning across clouds and jurisdictions while preserving confidentiality, minimizing data movement, and meeting compliance obligations
This document serves as a reference for the architectural design and implementation of a secure decentralized data sharing framework. The framework leverages Distributed Ledger Technology (DLT) to ensure data integrity and immutability, while incorporating multi-party computation, fully homomorphic encryption and Trusted Execution Environments for privacy preservation. The document also explores the GAIA-X framework to further strengthen data security within the decentralized environment.
The need for patient-centered electronic records that can store and retrieve the myriad details of a patient's medical history as documented during treatment has increased dramatically.These records are vital for future care, billing, or treatment.The distributed ledger technology known as Blockchain enables us to store this data and start and enable use at lightning speed while keeping the system transparent and secure.Using a distributed system with ledger capability allows for the safe and interoperable storage of records.With the elimination of mediators in financial and data transactions and in verifying data authenticity and ownership records, blockchain technology promises to alter the current state of digital asset transactions radically.Its extensive files and easy access to patients' medical histories are two of the most critical issues in healthcare, and its immutability, decentralization, and openness make it an ideal solution.Interoperability, the ability of various health organizations and software product makers to connect and exchange data securely and smoothly, is crucial to healthcare systems' practical and successful operation.Lack of interoperability is the root cause of many difficulties in contemporary healthcare, including data silos and disparate workflow tools.To solve this problem, a system that allows safe, recognized medical records to be kept in separate databases should be implemented.Using fog computing, which can decentralize data processing and handle massive amounts of data, we reviewed the literature and performed a system overview of blockchain technology in this study.Our ongoing experimental study highlights areas where current systems are lacking and suggests potential avenues for further research.
We present PineSU, a lightweight system that integrates Git with the Ethereum blockchain for sharing electronic documents, enabling decentralized integrity protection and timestamping. PineSU introduces the concept of Storage Unit (SU for short), which is essentially a Git repository along with some descriptor files needed to interact with the blockchain. SUs can be open or closed. Open SUs serve to secure Git repositories whose content may change in the future. At any moment, users can create a Blockchain Synchronization Point (BSP for short) of their open SUs. This allows for a rigorous integrity and authenticity verification of the corresponding digital documents. Whereas closed SUs are mainly a mechanism to invalidate any change to a Git repository. They are useful when a set of files must be definitively archived and made immutable, while enabling their sharing securely. As shown by a case study on clones of two public repositories on GitHub (owned by the Italian government) containing reports and data about the COVID-19 diffusion, PineSU has proven to be very effective in protecting Git repositories under a few security hypotheses that are easy to guarantee in many circumstances. Furthermore, an experimental and simulated performance evaluation demonstrates that the system scales well for storage units of increasing sizes and structure complexity. Finally, a qualitative comparison with existing solutions shows the strengths of PineSU against state-of-the-art approaches.