Abstract

The validity and integrity of digital evidence and the chain of custody are crucial to all digital forensic investigations. All new evidence and access logs of the original evidence should be logged in a document called the ‘chain of custody’. This document shows the timeline of any piece of evidence from the time it was recorded until the end of the investigation. In a traditional digital investigation, trusted parties, such as an investigator, are allowed access to the digital evidence and follow a strict process when dealing with data. These trusted parties have the capability to alter the data making the evidence inadmissible in a court of law. Alternatively, these trusted parties may also alter the data accidentally or with malicious intent, due to a lack of transparency and non-repudiation. Blockchain technology can solve this issue, however, existing research shows that adopting blockchain does not provide adequate transparent access control mechanisms. Consequently, this makes blockchain difficult to adopt due to the one-to-one mapping and the inability to easily validate the chain of custody and evidence admissibility. Current methodologies rely on an external off-chain access control mechanism, which, regrettably, remains susceptible to potential breaches that could compromise its integrity and validity. This paper proposes an enhanced model to provide access control through smart contracts, ensuring immutability, flexibility, transparency, and non-repudiation of both the access control mechanisms and the digital evidence itself. This is achieved by moving the access control mechanism to the blockchain. This tracks any changes made through the access control mechanism, further ensuring transparency and integrity. This smart contract-based access control builds off role-based access control, allowing for more complex hierarchies to be used. This model aims to allow for both modularity, making adoption easier for existing digital forensic tools, and encouraging digital investigation and litigation to become more streamlined. Existing tools can easily integrate with the proposed model adding an extra layer of non-repudiation, transparency, and integrity.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call