All problem statements
SIH26237SoftwareBlockchain & Cybersecurity

Cryptographic Attribution and Immutable Decryption Provenance for Multi-Recipient Encrypted Document Distribution

Ministry of Defence

Ideas submitted
45 / 500
Deadline
30 September 2026
Category
Software
Theme
Blockchain & Cybersecurity

Looks like it needs

BlockchainCybersecurity

Description

Sensitive documents are often distributed under a broadcast-encrypt, individually-decrypt model, where a sender encrypts a file once and each recipient decrypts it independently using their own credentials.

When such a file is shared with a single recipient, a leak is trivially attributable. However, when the same file is distributed to a group of recipients, every recipient who was capable of decrypting it becomes an equally plausible suspect if the file leaks, since the decrypted content is identical for all of them and carries no trace of which specific decryption produced the leaked copy.

Existing safeguards such as server-side access logs and static watermarks applied before distribution do not solve this. Access logs can be altered by a privileged administrator, and a watermark that is identical across all recipients reproduces the same attribution problem it is meant to solve.

Expected Outcome

Teams are expected to build a system that generates a unique, invisible forensic watermark at the moment of decryption, specific to each recipient's session, so that every decrypted copy is visually identical but forensically distinct.

Each decryption event must be cryptographically bound to the recipient's identity using a digital signature generated with the recipient's own private key, so that the recipient cannot later deny having decrypted the file.

This signed decryption record must be committed to an immutable, tamper-evident ledger, so that no single administrator or compromised account can retroactively alter or erase the record of who decrypted what and when.

Given a leaked copy of a distributed document, the solution should be able to extract the embedded watermark, look it up against the ledger, and return a cryptographically verifiable record identifying the exact recipient responsible.

Key Requirements

Generate a unique, invisible forensic watermark at the moment of decryption.

Make the watermark specific to each recipient and decryption session.

Ensure every decrypted copy is visually identical while remaining forensically distinct.

Cryptographically bind each decryption event to the recipient's identity.

Use the recipient's own private key to generate a digital signature for the decryption record.

Use NIST-standardized post-quantum cryptographic algorithms instead of classical cryptographic algorithms for Key Exchange and Digital Signatures.

Implement the immutable audit layer using blockchain or Distributed Ledger Technology (DLT).

Ensure that no single administrator or compromised account can retroactively modify or delete audit records.

Extract the forensic watermark from a leaked document.

Look up the extracted watermark against the immutable ledger.

Return a cryptographically verifiable record identifying the recipient associated with the decryption event.

Support complete operation within an offline and air-gapped environment.

Have no dependency on external cloud KMS services.

Have no dependency on public blockchain networks.

End-to-End Workflow

The sender encrypts the document and distributes it to authorized recipients.

An authorized recipient decrypts the document using their credentials.

The system generates a unique invisible forensic watermark tied to the recipient's decryption session.

The recipient signs the decryption record using their post-quantum private signing key.

The signed decryption record is committed to an offline, tamper-evident blockchain/DLT ledger.

The recipient receives a visually identical but uniquely fingerprinted decrypted document.

If the document is leaked, the forensic watermark is extracted from the leaked copy.

The extracted watermark is matched against the immutable ledger.

The associated post-quantum digital signature and ledger evidence are cryptographically verified.

The system produces a verifiable record identifying the recipient and corresponding decryption event.

Deployment Constraint

The complete system must run fully within an offline and air-gapped environment. All cryptographic operations, identity management, watermark generation, ledger operations, and forensic verification must function without external cloud services, cloud KMS infrastructure, or public blockchain networks.

How contested this one is

as of 28 Sept
45ideas submitted+14 in 2 days

That puts it 194th of the 240 statements that have any ideas at all, out of 240 on the board. It is moving, so the field here is already forming.

Added mid-season. This statement first appeared on 9 September, after the original list went out. Teams who shortlisted early have most likely never seen it.

See what the whole field is picking →

Counted from the official portal twice a day. The portal itself only shows today.

What a jury will ask about this

  1. 01“Who actually faces this problem today?”

    What works: Naming one real person and what they do instead right now. Reading the statement back is not an answer, they already read it.

  2. 02“This already exists. Why yours?”

    What works: That existing tools are consumer products. Yours is built for the ministry, works offline, in the local language, on official data.

  3. 03“Then why has nobody solved it yet?”

    What works: The real blocker. No connectivity, no incentive, nobody owns the data. You only know this if you read the ministry's own reports.

All 18 questions, with the trap answers →

More in Blockchain & Cybersecurity

See all →