Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Blockchain-Based Question Paper Security System

A secure, decentralized system for managing academic question papers using blockchain technology, ensuring integrity, traceability, and role-based access control.

🎯 Features

Core Functionality

  • Secure Upload: Encrypted question paper storage with IPFS integration
  • Role-Based Access: Admin, Moderator, Examiner, and Student roles with specific permissions
  • Approval Workflow: Moderator review and approval process for all papers
  • Audit Trail: Immutable blockchain logging of all system activities
  • Search & Filter: Advanced filtering by subject, difficulty, status, and more
  • AI-Assisted Paper Generation: Gemini-powered solution schemes and mixed question papers for different difficulty levels
  • Student Chatbot: “Clear Doubts” academic assistant for conceptual queries with persistent conversation history

Security Features

  • End-to-End Encryption: Files encrypted before leaving the browser
  • Blockchain Integrity: Smart contract verification for all operations
  • Access Control: Granular permissions based on user roles
  • Immutable Logs: All activities recorded permanently on blockchain
  • Secure PDF Viewer: Custom viewer with watermarking, and disabled download/print for student access

🏗️ Architecture

Frontend (React) → Backend (Node.js/Express) → Blockchain (Ethereum)
↓ ↓
Encryption Smart Contracts
↓ ↓
IPFS Storage Metadata & Logs

🛠️ Technology Stack

Blockchain

  • Ethereum with Solidity smart contracts
  • Hardhat for development and testing
  • Ganache for local blockchain
  • Web3.js for blockchain interaction

Backend

  • Node.js with Express.js
  • MongoDB for off-chain metadata
  • JWT for authentication
  • Multer for file handling
  • Crypto-js for encryption
  • Google Gemini (via @google/generative-ai) for solution schemes, paper generation, and chatbot

Frontend

  • React.js with Material-UI
  • Axios for API communication
  • React Router for navigation
  • PDF.js-based secure viewer with watermarking and restricted actions

📋 Prerequisites

  • Node.js (v16 or higher)
  • MongoDB
  • Ganache or local Ethereum node
  • Git

🚀 Installation & Setup

1. Clone Repository

git clone <repository-url>cd blockchain-question-paper-security

2. Install Dependencies

# Install backend dependencies
npm install
# Install frontend dependenciescd client
npm install
cd ..

3. Environment Configuration

# Copy environment template
cp .env.example .env
# Edit .env with your configuration# Update MongoDB URI, JWT secret, etc.

4. Start Services

Start MongoDB

# On Windows
net start MongoDB
# On macOS/Linux
sudo systemctl start mongod

Start Ganache

  • Open Ganache GUI and create a new workspace
  • Or use Ganache CLI: ganache-cli

5. Deploy Smart Contract

npm run compile
npm run deploy

6. Create Initial Admin User

After deploying the smart contract, you need to create an initial admin user:

# Create initial admin user in MongoDB
curl -X POST http://localhost:5000/api/init-admin

This creates an admin user with credentials:

7. Register Admin User in Blockchain

After creating the initial admin user, you need to register them in the blockchain:

# Login to get authentication token
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"admin@system.com","password":"admin123"}'# Use the token from the response to register the user in blockchain
curl -X POST http://localhost:5000/api/register-existing \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-d '{"address":"0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266","name":"System Admin","email":"admin@system.com","role":"Admin"}'

8. Start Application (Development)

# Terminal 1 – Start blockchain (Ganache)
ganache --port 7545 --accounts 10 --mnemonic "test test test test test test test test test test test junk"# Terminal 2 – Deploy contracts (after Ganache is running)
npm run deploy
# Terminal 3 – Backend API
npm run dev
# Terminal 4 – Frontend
npm run client

🎮 Usage

Access the Application

Default Admin Account

After contract deployment and following the setup steps above, you can log in with:

User Registration Important Note

All users must be registered in both MongoDB and the blockchain:

  1. Create users in MongoDB through the admin interface or API
  2. Register users in the blockchain using the admin panel or /api/register-existing endpoint

User Roles & Permissions

Admin

  • Full system access
  • User management (create, activate, deactivate)
  • Upload question papers
  • View all papers and audit logs

Moderator

  • Review and approve/reject papers
  • View audit logs
  • Download approved papers

Examiner

  • Upload question papers
  • Download approved papers

Student

  • View and download approved papers only

🧪 Testing

Smart Contract Tests

npm run test

API Testing

Use the provided Postman collection or test endpoints manually:

# Health check
curl http://localhost:5000/api/health
# Login (after creating users)
curl -X POST http://localhost:5000/api/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password"}'

📁 Project Structure

├── contracts/ # Solidity smart contracts
│ └── QuestionPaperSecurity.sol
├── scripts/ # Deployment scripts
│ └── deploy.js
├── test/ # Smart contract tests
│ └── QuestionPaperSecurity.test.js
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # React components
│ │ ├── contexts/ # React contexts
│ │ └── App.js
│ └── package.json
├── server.js # Express backend server
├── hardhat.config.js # Hardhat configuration
├── package.json # Backend dependencies
└── README.md

🔐 Security Considerations

Implemented Security Measures

  • File Encryption: AES encryption before IPFS storage
  • Access Control: Smart contract role-based permissions
  • Input Validation: Server-side validation for all inputs
  • JWT Authentication: Secure session management
  • Audit Logging: Immutable activity tracking

Production Recommendations

  • Use HTTPS in production
  • Implement rate limiting
  • Add input sanitization
  • Use environment-specific configurations
  • Regular security audits

🚀 Deployment

Local Development

Follow the installation steps above.

Production Deployment

Backend

  1. Set production environment variables
  2. Use PM2 for process management
  3. Configure reverse proxy (Nginx)
  4. Set up SSL certificates

Frontend

cd client
npm run build
# Deploy build folder to web server

Blockchain

  1. Deploy to testnet (Ropsten, Goerli)
  2. Update contract addresses in configuration
  3. For mainnet: Comprehensive security audit required

🤝 API Documentation

Authentication Endpoints

  • POST /api/login - User login
  • POST /api/register - Register new user (Admin only)
  • GET /api/profile - Get user profile

Paper Management

  • POST /api/upload - Upload question paper
  • GET /api/papers - Get all papers (filtered by role)
  • POST /api/papers/:id/approve - Approve paper (Moderator)
  • POST /api/papers/:id/reject - Reject paper (Moderator)
  • GET /api/papers/:id/download - Download paper

System

  • GET /api/health - System health check
  • GET /api/audit-logs - Get audit logs (Admin/Moderator)

🐛 Troubleshooting

Common Issues

Contract Deployment Fails

  • Ensure Ganache is running
  • Check network configuration in hardhat.config.js
  • Verify sufficient ETH in deployer account

MongoDB Connection Error

  • Verify MongoDB is running
  • Check connection string in .env
  • Ensure database permissions

Frontend Build Issues

  • Clear node_modules and reinstall
  • Check Node.js version compatibility
  • Verify all dependencies are installed

"User not registered" Error When Fetching Papers

This error occurs when a user exists in MongoDB but is not registered in the blockchain. To fix:

  1. Ensure the user is registered in the blockchain using the admin panel or API
  2. The user's address must match between MongoDB and blockchain

"Failed to fetch papers" Error

If you're getting this generic error:

  1. Check that the user is properly registered in both MongoDB and blockchain
  2. Verify that Ganache is running and accessible
  3. Check the server logs for more detailed error information

📈 Future Enhancements

Planned Features

  • IPFS Integration: Full decentralized storage
  • Multi-signature Approval: Multiple moderator approval
  • Paper Versioning: Track paper revisions
  • Notification System: Email/SMS notifications
  • Analytics Dashboard: Usage statistics and insights
  • Mobile App: React Native mobile application

Scalability Improvements

  • Layer 2 Solutions: Polygon/Arbitrum integration
  • Microservices: Service decomposition
  • Caching: Redis implementation
  • CDN: Content delivery optimization

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

📞 Support

For support and questions:

  • Create an issue in the repository
  • Contact the development team
  • Check the troubleshooting section

🙏 Acknowledgments

  • Ethereum Foundation for blockchain technology
  • OpenZeppelin for smart contract security patterns
  • React team for the frontend framework
  • All contributors and testers

About

A complete question paper management system

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages