Cerebrum
Blockchain-Based Secure Examination Paper Distribution System
Overview
Cerebrum is a cryptographically secure examination paper management and distribution platform that eliminates paper leaks, insider threats, and metadata tampering through a layered security architecture combining modern cryptography, decentralized storage, and blockchain-backed verification.
Traditional examination systems rely on centralized infrastructure with weak access controls and no tamper evidence. Cerebrum addresses this with:
| Problem | Cerebrum's Solution |
|---|---|
| Paper leaks | AES-256 encryption + timed release |
| Insider threats | Role-based access control + audit logging |
| Data tampering | SHA-256 hashing + RSA digital signatures |
| Centralized failure | IPFS decentralized storage |
| No accountability | Immutable blockchain anchoring |
| Weak audit trails | Forensic audit dashboard with live event stream |
Screenshots
![]() | ![]() |
![]() | ![]() |
![]() | ![]() |
![]() | ![]() |

Architecture

Tech Stack
Frontend
| Technology | Version | Purpose |
|---|---|---|
| Next.js | 16 | Full-stack React framework, App Router |
| React | 19 | UI component library |
| TypeScript | 5 | Type-safe development |
| Tailwind CSS | 4 | Utility-first styling |
| GSAP | 3 | High-performance animations |
| Three.js | 0.184 | 3D WebGL particle backgrounds |
| Framer Motion | 12 | Declarative UI animations |
Backend
| Technology | Version | Purpose |
|---|---|---|
| Next.js API Routes | 16 | Serverless API endpoints |
| Prisma ORM | 6 | Type-safe database client |
| bcryptjs | 3 | Password hashing |
| jsonwebtoken | 9 | JWT authentication |
Database & Storage
| Technology | Purpose |
|---|---|
| PostgreSQL | Primary relational database |
| Neon | Serverless PostgreSQL hosting |
| IPFS via Pinata | Decentralized encrypted artifact storage |
Cryptography
| Algorithm | Implementation | Purpose |
|---|---|---|
| AES-256-CBC | Node.js crypto | Symmetric encryption of examination papers |
| SHA-256 | Node.js crypto | Integrity hashing of encrypted artifacts |
| RSA-2048 | Node.js crypto | Digital signature generation and verification |
| AES-256-CBC | Node.js crypto | Vault encryption of AES keys and RSA private key |
Blockchain
| Technology | Version | Purpose |
|---|---|---|
| Solidity | 0.8.28 | Smart contract language |
| Hardhat | 2 | Ethereum development environment |
| Hardhat Ignition | — | Declarative contract deployment |
| Ethers.js | 6 | Blockchain interaction library |
| Ethereum Sepolia | — | Public testnet deployment |
Security Architecture
| Layer | Mechanism | Implementation |
|---|---|---|
| Confidentiality | Symmetric encryption | AES-256-CBC per paper |
| Key Protection | Vault encryption | AES keys encrypted with MASTER_KEY |
| Integrity | Cryptographic hashing | SHA-256 of encrypted artifact |
| Authenticity | Digital signatures | RSA-2048 sign/verify |
| Immutability | Blockchain anchoring | Sepolia testnet, onlyOwner contract |
| On-chain Verification | Cross-check at decrypt | DB record verified against chain before release |
| Availability | Decentralized storage | IPFS via Pinata |
| Accountability | Immutable audit trail | Every action logged with user, role, timestamp |
| Authorization | Role-based access | 5 roles, server-side enforcement on every route |
| Brute-force Protection | IP rate limiting | 10 attempts / 15-minute window |
Role-Based Access Control
| Role | Signup | Upload | Release | Download | Audit Logs | User Management |
|---|---|---|---|---|---|---|
SUPER_ADMIN | Admin CLI only | ✅ | ✅ | ✅ | ✅ | ✅ |
EXAM_CONTROLLER | Admin CLI only | ❌ | ✅ | ✅ | ✅ | ❌ |
PAPER_SETTER | Public signup | ✅ | ❌ | ❌ | ❌ | ❌ |
AUDITOR | Public signup | ❌ | ❌ | ❌ | ✅ | ❌ |
INVIGILATOR | Public signup | ❌ | ❌ | ✅ | ❌ | ❌ |
Super Admin and Exam Controller cannot be created via public signup. Use
npm run create-adminto provision privileged accounts directly — this prevents privilege escalation through the public registration endpoint.
Smart Contract
Contract Address (Sepolia): 0x080a57357A2fA658237a7d77e49E3998Bb091A1C
function storePaper(string cid, string hash, string signature) onlyOwner
function getPaper(uint256 index) view returns (cid, hash, signature, timestamp, uploadedBy)
function totalPapers() view returns (uint256)
function transferOwnership(address newOwner) onlyOwner
The onlyOwner modifier ensures only the configured backend wallet can write records. At decrypt time, the application reads the on-chain record and cross-checks it against the database — so the blockchain is doing real verification work, not just write-only logging.
Database Schema
User ──────────────────── Paper ─────────────────── AuditLog
│ id (uuid) │ id (cuid) │ id
│ email (unique) │ fileName │ action (enum)
│ password (bcrypt) │ encryptedAesKey │ timestamp
│ name │ vaultIv │ userId → User
│ role (enum) │ iv │ paperId → Paper
│ createdAt │ cid
│ │ hash
│ ──▶ uploadedPapers[] │ signature
│ ──▶ auditLogs[] │ publicKey
│ txHash
KeyVault │ encryptedPath
│ id │ decryptedPath (null)
│ publicKey │ uploadedAt
│ privateKey (encrypted) │ uploadedById → User
│ privateKeyIv │ unlockAt
│ createdAt │ isUnlocked
│ status (enum)
Setup & Installation
Prerequisites
- Node.js 20+
- PostgreSQL database (Neon free tier works)
- Pinata account for IPFS pinning
- Alchemy account for Sepolia RPC (optional, for testnet)
Local Development
# 1. Clone the repository
git clone https://github.com/AaryanBairagi/Cerebrum.git
cd Cerebrum
# 2. Install dependencies
npm install
# 3. Configure environment
cp .env.example .env
# Fill in DATABASE_URL, PINATA_JWT, JWT_SECRET, MASTER_KEY
# 4. Sync database schema
npx prisma db push
# 5. Create a Super Admin account
npm run create-admin
# 6. Start local blockchain (separate terminal)
npx hardhat node
# 7. Compile and deploy contract to local network
npx hardhat compile
npx hardhat run lib/scripts/deploy.js --network localhost
# → Copy printed address to .env as CONTRACT_ADDRESS
# → Set RPC_URL=http://127.0.0.1:8545
# 8. Start the app
npm run dev
Visit http://localhost:3000 and sign in with the Super Admin account.
Testnet Deployment (Sepolia)
# Add to .env:
# SEPOLIA_RPC_URL=https://eth-sepolia.g.alchemy.com/v2/your-key
# PRIVATE_KEY=0xYourThrowawayWalletKey (fund with free ETH from sepoliafaucet.com)
npx hardhat ignition deploy ignition/modules/Cerebrum.js --network sepolia
# → Copy printed address to .env as CONTRACT_ADDRESS
# → Set RPC_URL to same Alchemy URL
# Run contract tests
npx hardhat test
Environment Variables
| Variable | Required | Description |
|---|---|---|
DATABASE_URL | ✅ | PostgreSQL connection string |
PINATA_JWT | ✅ | Pinata API JWT for IPFS uploads |
JWT_SECRET | ✅ | Secret for signing auth tokens |
MASTER_KEY | ✅ | 64-char hex key for vault encryption |
RPC_URL | ✅ | Ethereum RPC endpoint (local or Sepolia) |
PRIVATE_KEY | ✅ | Backend wallet private key (throwaway for testnet) |
CONTRACT_ADDRESS | ✅ | Deployed Cerebrum contract address |
SEPOLIA_RPC_URL | Optional | Alchemy/Infura Sepolia URL for testnet deploy |
CONTRACT_OWNER_ADDRESS | Optional | Override deployer address in deploy script |
Current Status & Known Tradeoffs
This is a working, complete demonstration of the full lifecycle:
encrypt → sign → pin → anchor → time-gate → verify on-chain → decrypt → stream
| Feature | Status |
|---|---|
| AES-256 paper encryption | ✅ Production-quality |
| RSA-2048 digital signatures | ✅ Production-quality |
| IPFS decentralized storage | ✅ Production-quality |
| Blockchain anchoring (Sepolia) | ✅ Live deployed contract |
| On-chain verification at decrypt time | ✅ Implemented |
| In-memory buffer streaming (no disk write) | ✅ Implemented |
| IP-based login rate limiting | ✅ Implemented |
| RSA private key encrypted at rest | ✅ Implemented |
| Role-gated Admin + Auditor dashboards | ✅ Implemented |
onlyOwner smart contract access control | ✅ Implemented |
| Redis-backed rate limiting | ❌ In-memory only (resets on restart) |
| Pure httpOnly cookie auth | ❌ JWT also in localStorage |
| Multi-node network | ❌ Single chain by design |
Future Enhancements
- Multi-signature approval workflows
- Hardware Security Module (HSM) integration
- Cloud KMS for private key management
- Redis-backed rate limiting for multi-instance deployments
- Zero-Knowledge proof verification
- AI-based anomaly detection in audit stream
- Multi-provider IPFS replication
- Hyperledger Fabric migration for private consortium chains
License
MIT — see LICENSE.
Built as an academic/portfolio demonstration of a production-grade secure examination infrastructure. See "Current Status & Known Tradeoffs" above before considering production use.










