Blockchain-Based Secure Platform for Identity, Access Control, and Digital Asset Management
AegisID is a secure identity and digital asset management platform designed around decentralized identity, verifiable credentials, role-based access control, and blockchain-backed integrity verification.
The project is built as a prototype for Smart India Hackathon (SIH) 2026 β Problem Statement SIH26125.
- JWT-based authentication
- Role-Based Access Control (RBAC)
- Fine-grained permission-based API authorization
- User account status enforcement
- Protected backend APIs
- WebAuthn support in the backend
- Identity management
- Decentralized Identifier (DID) support
- Identity verification status
- Identity lifecycle status
- SHA-256 identity hashing
- Blockchain anchoring of identity proofs
- Create and manage verifiable credentials
- Credential hashing
- Credential verification
- Credential validation
- Credential lifecycle management
- Revoke / reactivate / expire credentials
- Blockchain anchoring
- Create digital assets
- Update asset information
- Assign assets
- Transfer ownership
- Revoke and restore assets
- Asset integrity verification
- Blockchain-backed asset records
- Solidity smart contract
- Local EVM blockchain using Hardhat
- Spring Boot β blockchain integration using Web3j
- Identity, credential and asset anchoring
- On-chain status and ownership updates
- Blockchain transaction tracking
- Transaction hash, block number and gas usage records
βββββββββββββββββββββββ
β React / Vite UI β
ββββββββββββ¬βββββββββββ
β REST API
βΌ
βββββββββββββββββββββββ
β Spring Boot API β
β Java 17 β
ββββββββββββ¬βββββββββββ
β
βββββββββββββββββββββΌββββββββββββββββββββ
β β β
βΌ βΌ βΌ
ββββββββββββββββ ββββββββββββββββ ββββββββββββββββ
β MySQL β β JWT / RBAC β β Web3j β
β Persistent DBβ β Security β β Blockchain β
ββββββββββββββββ ββββββββββββββββ ββββββββ¬ββββββββ
β
βΌ
ββββββββββββββββββββ
β Solidity Registryβ
β EVM / Hardhat β
ββββββββββββββββββββ
Sensitive information is intended to remain off-chain.
MySQL
βββ Identity metadata
βββ Credential data
βββ User / role / permission data
βββ Digital asset metadata
βββ Blockchain transaction records
Blockchain
βββ Cryptographic proofs / hashes
βββ Wallet addresses
βββ Integrity/status records
βββ Transaction history
Passwords, private keys, and sensitive personal documents should never be stored on-chain.
| Layer | Technology |
|---|---|
| Frontend | React + Vite |
| Backend | Java 17 + Spring Boot |
| Database | MySQL |
| Authentication | Spring Security + JWT |
| Access Control | RBAC + Permissions |
| Web3 Integration | Web3j |
| Smart Contract | Solidity |
| Blockchain | EVM / Hardhat |
| Build Tool | Maven |
| Frontend Package Manager | npm |
AegisID/
β
βββ blockchain/
β βββ contracts/
β β βββ AegisIDRegistry.sol
β βββ ignition/
β β βββ modules/
β β βββ AegisIDRegistry.ts
β βββ hardhat.config.ts
β βββ package.json
β
βββ backend/
β βββ backend/
β βββ pom.xml
β βββ mvnw
β βββ mvnw.cmd
β βββ src/
β βββ main/
β βββ java/
β β βββ com/AegisID/backend/
β βββ resources/
β
βββ src/
β βββ App.tsx
β βββ main.tsx
β βββ index.css
β
βββ public/
βββ package.json
βββ README.md
Install:
- Node.js
- npm
- Java 17+
- Maven (optional because Maven Wrapper is included)
- MySQL
- Git
Make sure your MySQL server is running and the AegisID database is available.
Example:
CREATE DATABASE aegisid;Configure the database credentials using environment variables rather than committing passwords.
Open Terminal 1:
cd D:\projects\AegisID\blockchain
npm install
npx hardhat nodeThe local blockchain runs at:
http://127.0.0.1:8545
Default Hardhat chain ID:
31337
Keep this terminal running.
The development deployment used by the project is:
0x5FbDB2315678afecb367f032d93F642f64180aa3
If the Hardhat network is reset and the contract is redeployed, update the backend contract address accordingly.
Open Terminal 2:
cd D:\projects\AegisID\backend\backend
.\mvnw.cmd spring-boot:runOr, if Maven is installed globally:
mvn spring-boot:runBackend URL:
http://localhost:8080
Health endpoint:
http://localhost:8080/api/health
Open Terminal 3:
cd D:\projects\AegisID
npm install
npm run devVite normally starts the frontend at:
http://localhost:5173
Protected endpoints require a JWT.
Login first through the authentication API and use the returned token in:
Authorization: Bearer <JWT>Example:
GET /api/users
Authorization: Bearer eyJ...Authorization is controlled through permissions such as:
USER_READ
IDENTITY_READ
IDENTITY_CREATE
CREDENTIAL_READ
CREDENTIAL_CREATE
CREDENTIAL_VERIFY
ASSET_READ
ASSET_MINT
ASSET_TRANSFER
ASSET_REVOKE
The exact permission required depends on the endpoint.
The backend exposes REST APIs for:
/api/auth/*
/api/users/*
/api/identities/*
/api/credentials/*
/api/assets/*
/api/blockchain/*
/api/health
Major blockchain operations include:
GET /api/blockchain/status
GET /api/blockchain/contract
GET /api/blockchain/identity/{identityHash}
POST /api/blockchain/identity/anchor
GET /api/blockchain/credential/{credentialHash}
POST /api/blockchain/credential/anchor
GET /api/blockchain/credential/{credentialId}/verify
GET /api/blockchain/asset/{assetHash}
POST /api/blockchain/asset/anchor
PUT /api/blockchain/asset/{assetHash}/status
PUT /api/blockchain/asset/{assetHash}/owner
For frontend integration, treat the backend implementation and API responses as the source of truth.
The main Solidity contract is:
AegisIDRegistry
It maintains blockchain records for:
- Identity
- Verifiable Credential
- Digital Asset
Conceptually:
Identity Hash ββββββββΊ Identity Record
Credential Hash ββββββΊ Credential Record
Asset Hash βββββββββββΊ Asset Record
Each record contains blockchain-level information such as:
- hash
- wallet/owner address
- timestamp
- active status
User
β
βΌ
Authentication
β
βΌ
Role + Permission Check
β
βΌ
Digital Identity / DID
β
βΌ
Verifiable Credential
β
βΌ
SHA-256 Hash
β
βΌ
Blockchain Anchor
β
βΌ
Blockchain Transaction
β
βΌ
Integrity Verification
β
βΌ
Digital Asset Management
Before a demo, verify the three services are running:
127.0.0.1:8545
localhost:8080
localhost:5173
Recommended smoke-test sequence:
1. MySQL running
2. Hardhat node running
3. Spring Boot starts successfully
4. /api/health returns 200
5. Login returns JWT
6. Protected API works with JWT
7. Blockchain status works with JWT
8. Blockchain read works
9. Blockchain write creates a confirmed transaction
10. Frontend can consume the API
For development and hackathon deployment:
- Keep JWT secrets outside source control.
- Keep database passwords outside source control.
- Keep blockchain private keys outside source control.
- Use environment variables for secrets.
- Never commit production credentials.
- Never store passwords or private keys on the blockchain.
- Remove debug logging before final deployment.
- Return DTOs instead of exposing internal entities containing sensitive fields.
Example environment variables:
JWT_SECRET
DB_USERNAME
DB_PASSWORD
BLOCKCHAIN_RPC_URL
BLOCKCHAIN_CONTRACT_ADDRESS
BLOCKCHAIN_PRIVATE_KEY
Create your own local .env / IDE environment configuration as appropriate. Do not commit secret values.
AegisID demonstrates the following end-to-end concept:
Login
β
Authenticated User
β
Identity / DID
β
Credential Creation
β
Credential Hash
β
Blockchain Anchoring
β
Credential Verification
β
Digital Asset Creation
β
Blockchain Asset Anchor
β
Ownership Transfer
β
Asset Status Management
β
Blockchain Verification
The goal is to demonstrate how identity, access control, verifiable credentials, and digital asset integrity can work together using blockchain technology.
Hackathon MVP: Ready for integration and demonstration π
Current focus:
- Frontend β Backend integration
- End-to-end testing
- Deployment
- Demo preparation
- Presentation / PPT
The backend is considered feature-frozen for the hackathon. New features should only be added if they are required to fix an integration or demonstration blocker.
AegisID β SIH26125
Blockchain-based secure platform for:
Identity β’ Access Control β’ Verifiable Credentials β’ Digital Asset Management
Built for Smart India Hackathon 2026.
https://gitdiagram.com/SOUMYAJIT200515/AegisID
AegisID is licensed under the MIT License.
Copyright (c) 2026 Soumyajit Saha
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN