Cerebrum landing page
In progress

Cerebrum

Decentralized exam integrity platform, built to stop paper leaks at the infrastructure level.

Domain

cerebrum-delta.vercel.app

Stack

SolidityBlockchainRSAAES-256Node.jsTypeScript

Cerebrum

Blockchain-Based Secure Examination Paper Distribution System

MIT License Next.js TypeScript Solidity Deployed on Vercel Contract on Sepolia

Live Demo · Deployed Contract · Report Bug


Overview

Cerebrum is a cryptographically secure examination paper management and distribution platform that eliminates paper leaks, insider threats, and metadata tampering through a layered security architecture combining modern cryptography, decentralized storage, and blockchain-backed verification.

Traditional examination systems rely on centralized infrastructure with weak access controls and no tamper evidence. Cerebrum addresses this with:

ProblemCerebrum's Solution
Paper leaksAES-256 encryption + timed release
Insider threatsRole-based access control + audit logging
Data tamperingSHA-256 hashing + RSA digital signatures
Centralized failureIPFS decentralized storage
No accountabilityImmutable blockchain anchoring
Weak audit trailsForensic audit dashboard with live event stream

Screenshots

12
34
56
78

9


Architecture

Cerebrum Architecture


Tech Stack

Frontend

TechnologyVersionPurpose
Next.js16Full-stack React framework, App Router
React19UI component library
TypeScript5Type-safe development
Tailwind CSS4Utility-first styling
GSAP3High-performance animations
Three.js0.1843D WebGL particle backgrounds
Framer Motion12Declarative UI animations

Backend

TechnologyVersionPurpose
Next.js API Routes16Serverless API endpoints
Prisma ORM6Type-safe database client
bcryptjs3Password hashing
jsonwebtoken9JWT authentication

Database & Storage

TechnologyPurpose
PostgreSQLPrimary relational database
NeonServerless PostgreSQL hosting
IPFS via PinataDecentralized encrypted artifact storage

Cryptography

AlgorithmImplementationPurpose
AES-256-CBCNode.js cryptoSymmetric encryption of examination papers
SHA-256Node.js cryptoIntegrity hashing of encrypted artifacts
RSA-2048Node.js cryptoDigital signature generation and verification
AES-256-CBCNode.js cryptoVault encryption of AES keys and RSA private key

Blockchain

TechnologyVersionPurpose
Solidity0.8.28Smart contract language
Hardhat2Ethereum development environment
Hardhat Ignition—Declarative contract deployment
Ethers.js6Blockchain interaction library
Ethereum Sepolia—Public testnet deployment

Security Architecture

LayerMechanismImplementation
ConfidentialitySymmetric encryptionAES-256-CBC per paper
Key ProtectionVault encryptionAES keys encrypted with MASTER_KEY
IntegrityCryptographic hashingSHA-256 of encrypted artifact
AuthenticityDigital signaturesRSA-2048 sign/verify
ImmutabilityBlockchain anchoringSepolia testnet, onlyOwner contract
On-chain VerificationCross-check at decryptDB record verified against chain before release
AvailabilityDecentralized storageIPFS via Pinata
AccountabilityImmutable audit trailEvery action logged with user, role, timestamp
AuthorizationRole-based access5 roles, server-side enforcement on every route
Brute-force ProtectionIP rate limiting10 attempts / 15-minute window

Role-Based Access Control

RoleSignupUploadReleaseDownloadAudit LogsUser Management
SUPER_ADMINAdmin CLI only✅✅✅✅✅
EXAM_CONTROLLERAdmin CLI only❌✅✅✅❌
PAPER_SETTERPublic signup✅❌❌❌❌
AUDITORPublic signup❌❌❌✅❌
INVIGILATORPublic signup❌❌✅❌❌

Super Admin and Exam Controller cannot be created via public signup. Use npm run create-admin to provision privileged accounts directly — this prevents privilege escalation through the public registration endpoint.


Smart Contract

Contract Address (Sepolia): 0x080a57357A2fA658237a7d77e49E3998Bb091A1C

function storePaper(string cid, string hash, string signature) onlyOwner
function getPaper(uint256 index) view returns (cid, hash, signature, timestamp, uploadedBy)
function totalPapers() view returns (uint256)
function transferOwnership(address newOwner) onlyOwner

The onlyOwner modifier ensures only the configured backend wallet can write records. At decrypt time, the application reads the on-chain record and cross-checks it against the database — so the blockchain is doing real verification work, not just write-only logging.


Database Schema

User ──────────────────── Paper ─────────────────── AuditLog
│ id (uuid)              │ id (cuid)               │ id
│ email (unique)         │ fileName                │ action (enum)
│ password (bcrypt)      │ encryptedAesKey         │ timestamp
│ name                   │ vaultIv                 │ userId → User
│ role (enum)            │ iv                      │ paperId → Paper
│ createdAt              │ cid
│                        │ hash
│ ──▶ uploadedPapers[]   │ signature
│ ──▶ auditLogs[]        │ publicKey
                         │ txHash
KeyVault                 │ encryptedPath
│ id                     │ decryptedPath (null)
│ publicKey              │ uploadedAt
│ privateKey (encrypted) │ uploadedById → User
│ privateKeyIv           │ unlockAt
│ createdAt              │ isUnlocked
                         │ status (enum)

Setup & Installation

Prerequisites

  • Node.js 20+
  • PostgreSQL database (Neon free tier works)
  • Pinata account for IPFS pinning
  • Alchemy account for Sepolia RPC (optional, for testnet)

Local Development

# 1. Clone the repository
git clone https://github.com/AaryanBairagi/Cerebrum.git
cd Cerebrum

# 2. Install dependencies
npm install

# 3. Configure environment
cp .env.example .env
# Fill in DATABASE_URL, PINATA_JWT, JWT_SECRET, MASTER_KEY

# 4. Sync database schema
npx prisma db push

# 5. Create a Super Admin account
npm run create-admin

# 6. Start local blockchain (separate terminal)
npx hardhat node

# 7. Compile and deploy contract to local network
npx hardhat compile
npx hardhat run lib/scripts/deploy.js --network localhost
# → Copy printed address to .env as CONTRACT_ADDRESS
# → Set RPC_URL=http://127.0.0.1:8545

# 8. Start the app
npm run dev

Visit http://localhost:3000 and sign in with the Super Admin account.

Testnet Deployment (Sepolia)

# Add to .env:
# SEPOLIA_RPC_URL=https://eth-sepolia.g.alchemy.com/v2/your-key
# PRIVATE_KEY=0xYourThrowawayWalletKey (fund with free ETH from sepoliafaucet.com)

npx hardhat ignition deploy ignition/modules/Cerebrum.js --network sepolia
# → Copy printed address to .env as CONTRACT_ADDRESS
# → Set RPC_URL to same Alchemy URL

# Run contract tests
npx hardhat test

Environment Variables

VariableRequiredDescription
DATABASE_URL✅PostgreSQL connection string
PINATA_JWT✅Pinata API JWT for IPFS uploads
JWT_SECRET✅Secret for signing auth tokens
MASTER_KEY✅64-char hex key for vault encryption
RPC_URL✅Ethereum RPC endpoint (local or Sepolia)
PRIVATE_KEY✅Backend wallet private key (throwaway for testnet)
CONTRACT_ADDRESS✅Deployed Cerebrum contract address
SEPOLIA_RPC_URLOptionalAlchemy/Infura Sepolia URL for testnet deploy
CONTRACT_OWNER_ADDRESSOptionalOverride deployer address in deploy script

Current Status & Known Tradeoffs

This is a working, complete demonstration of the full lifecycle:

encrypt → sign → pin → anchor → time-gate → verify on-chain → decrypt → stream

FeatureStatus
AES-256 paper encryption✅ Production-quality
RSA-2048 digital signatures✅ Production-quality
IPFS decentralized storage✅ Production-quality
Blockchain anchoring (Sepolia)✅ Live deployed contract
On-chain verification at decrypt time✅ Implemented
In-memory buffer streaming (no disk write)✅ Implemented
IP-based login rate limiting✅ Implemented
RSA private key encrypted at rest✅ Implemented
Role-gated Admin + Auditor dashboards✅ Implemented
onlyOwner smart contract access control✅ Implemented
Redis-backed rate limiting❌ In-memory only (resets on restart)
Pure httpOnly cookie auth❌ JWT also in localStorage
Multi-node network❌ Single chain by design

Future Enhancements

  • Multi-signature approval workflows
  • Hardware Security Module (HSM) integration
  • Cloud KMS for private key management
  • Redis-backed rate limiting for multi-instance deployments
  • Zero-Knowledge proof verification
  • AI-based anomaly detection in audit stream
  • Multi-provider IPFS replication
  • Hyperledger Fabric migration for private consortium chains

License

MIT — see LICENSE.

Built as an academic/portfolio demonstration of a production-grade secure examination infrastructure. See "Current Status & Known Tradeoffs" above before considering production use.


Built by Aaryan Bairagi