Nathaniel Sauer

Cybersecurity and software engineer

All work

bchoc

Blockchain chain-of-custody ledger for digital evidence, in Python

start heresecuritycoursework

What it is

A command-line tool that keeps a tamper-evident chain of custody for digital forensic evidence. Every action on an evidence item becomes a block in a blockchain, so an edit to an earlier record breaks verification of the chain.

What I built

Our team of five wrote it in Python for CSE 469, using PyCryptodome for the cryptography and argparse for the command line. The commands follow a real evidence workflow:

  • add a new item to a case
  • checkout and checkin an item as it moves between people
  • remove an item from the chain
  • verify the whole chain

How it works

Each block is encrypted with AES-256 and hashed with SHA-256. A block stores the hash of the block before it, so the blocks form a hash-linked chain. verify walks the chain from the first block and reports whether every link still matches:

$ python3 ./bchoc.py verify
State of blockchain: CLEAN