Auditchain: a mechanism for ensuring logs integrity based on proof of existence in a public blockchain

Bruno Mendonça, Paulo Matias · 2021

Digital data are critical to people and companies, acting as a crucial element in the decision-making process in different areas. Accordingly, logs can track how this data changes over time and are essential to enable auditing. The traditional approach to ensure log integrity is to store them on well-kept servers, both from a physical and a digital security standpoint. However, this approach assumes that it is difficult to exploit these servers' vulnerabilities and that these systems' administrator is honest. Distributing trust is an alternative that does not rely on these assumptions, and blockchain-based approaches are promising in that aspect. A method that stands out for providing post-storage integrity guarantees at low transaction costs is the proof of existence, which consists of sending the hash of an object to a public blockchain, proving that the object existed before its hash became included in the blockchain. However, although this method is viable, no other works generalize the concept nor make it accessible, making its wide adoption difficult. Therefore, this work aims to propose an architecture to assure log integrity through proof of existence and develop an application for consuming logs indexed using Elasticsearch: the Auditchain. We present here a case study with qualitative and quantitative data collection. As a result, we obtained a comparison of PoE fulfillment APIs, an architecture to simplify PoE of logs, and an implementation of the proposed architecture.

Read the paper · More papers on PaperTik