BlockLedger replaces centralized identity and asset registries with self-sovereign DIDs, NFT-bound asset ownership and smart-contract-enforced role permissions. Every identity creation, mint, allocation, permission change and transfer is written to a hash-chained ledger anchored on-chain — verifiable by anyone, alterable by no one.
Centralized IAM concentrates every credential behind one perimeter, and asset ownership is scattered across disconnected systems where provenance cannot be checked. BlockLedger removes both single points of failure.
Every participant holds a self-sovereign DID of the form did:blkl:sol:<pubkey>, derived from their own keypair. No central directory issues it and no administrator can silently revoke it — authentication is a cryptographic proof, not a database lookup.
Documents, design files, firmware images, certificates, licences and hardware passports are minted as NFTs. Each token is unique, traceable and bound directly to a holder's DID, creating a permanent and unforgeable link between the asset and its owner.
Minting, allocation, transfer and validation rules live in contract logic rather than in application code. Only authorized administrators can mint and assign assets, so unauthorized duplication or reassignment fails at the protocol layer instead of being caught after the fact.
Four roles — Admin, Manager, Auditor and User — are attached to identities, not to sessions. Administrators define which permissions each role carries, and the contracts evaluate that matrix on every single operation.
Identity creation, NFT minting, asset allocation, permission changes and ownership transfers are appended to a hash-chained ledger where every entry commits to the hash of the one before it. Altering any historical record breaks the chain and is detected immediately.
Payloads are addressed by their own hash rather than by location. The content identifier is what gets recorded on-chain, so a retrieved file either hashes back to the recorded value or it is not the file that was registered.
Audit-chain checkpoints are committed to Solana devnet, so the record of who holds what — and who was allowed to change it — is verifiable outside BlockLedger itself. Where network credentials are not configured, the platform falls back to a clearly-labelled local simulation rather than pretending an anchor exists.
Four operations cover the whole lifecycle. Each one leaves a record that the next one can be checked against.
A keypair produces a decentralized identifier — did:blkl:sol:<pubkey>. BlockLedger assembles a W3C-shaped DID Document containing the Ed25519 verification method and pins it to IPFS. The identity belongs to the holder; the platform only records that it exists.
The file — a document, design file, firmware image, certificate, licence or hardware passport — is hashed with SHA-256, pinned to IPFS, and minted as a token whose owner field is the holder's DID. Only an Admin may mint, enforced in contract logic.
Admin, Manager, Auditor and User are mapped to explicit permissions against each identity. Every subsequent operation is evaluated against that matrix, and calls made without the required permission revert rather than degrade silently.
Each of the preceding actions appends an entry that commits to the hash of the previous one. Re-running the chain check recomputes every link and anchors a checkpoint on Solana devnet, so any edit to history is surfaced rather than absorbed.
Run the full sequence yourself — the platform ships with the registry, the permission matrix and the audit chain already wired together.
Environments where an access log is not sufficient evidence and the authenticity of an artefact must be independently checkable.
Sub-assemblies, tooling records and build sheets move between plants and partners. Binding each record to a DID makes the holder of every revision explicit, and reassignment requires an authorized administrator rather than a shared folder permission.
Classified drawings, tender documents and signed approvals are hashed before storage. Custody changes are ledger entries, so the question is not who currently has access but who has ever held it.
A firmware image or PCB design is registered by its SHA-256 digest. Anything later presented as that artefact either hashes to the recorded value or is demonstrably not the artefact that was registered.
External parties receive an identity with a scoped role instead of a shared credential. Permissions are evaluated by contract on every operation and withdrawn by changing the role, which is itself an audited event.
Calibration certificates, test reports and software licences are minted as non-duplicable tokens. Verification is a lookup against the issuing identity, not a phone call to the issuer.
Auditors get a role that can read the full trail without the ability to mutate it. The chain check recomputes every link, so an audit is a computation rather than a request for cooperation.
Technical surface
Smart India Hackathon · PS 26125 · Bharat Electronics Limited