CASE STUDY / PROOF OF CONCEPT

Blockchain and IPFS notarisation: a verifiable proof.

The PoC developed within Project360 connects hashing, cryptography, distributed storage and smart contracts in a complete flow: from file selection to later verification, including a privacy mode that records the digital fingerprint only.

Technical notarisation flow with SHA-256, encryption, IPFS and a Polygon smart contract
Project360 internal PoCItalyTechnology experiment
SHA-256File fingerprint
Client-sideOptional AES-CTR encryption
On-chain + IPFSProof and asset kept separate
Project360 internal PoCOrganisation / project
Project statusExperiment

FROM ASSET TO EVIDENCE

A readable technical chain with explicit choices.

INTEGRITY

The hash as a stable reference

Project360 developed a path in which the browser calculates the original file’s SHA-256 fingerprint and uses it as a stable reference. The content does not need to be published on-chain to remain verifiable later.

Verification can start from a file, identifier, hash or CID, depending on the available evidence.

PRIVACY

Encrypted copy or on-chain proof only

The PoC integrates two paths designed by Project360: an AES-CTR encrypted copy stored on IPFS through Lighthouse, or a privacy mode that records only the hash in the smart contract.

The key is generated client-side, making custody responsibilities visible and enabling a serious discussion of requirements, roles and procedures before an operational service is designed.

Two paths share the same evidence: an encrypted IPFS asset or an on-chain fingerprint only.

Why notarise a digital asset

Documents, designs and content can change, be duplicated or circulate outside the system that created them. Notarisation establishes verifiable time-based evidence of a file’s existence and integrity. The PoC studies this principle without turning the blockchain into a content repository.

Evidence separated from preservation

The smart contract records the information needed for verification, while IPFS is involved only when a distributed copy is useful. This separation avoids confusing proof with storage and supports different processes for intellectual property, project documents, traceability or inter-organisational exchange.

Cryptography in the browser

The file can be encrypted before leaving the device. The PoC uses AES-CTR and records both the original and encrypted hashes on-chain, together with the CID and timestamp. Key custody remains a process concern rather than an implementation detail hidden by the interface.

Verification and certification

Verification can start from an identifier, hash, file or CID. The system compares fingerprints, retrieves the registered data and, when the encrypted content and key are available, supports decryption. A PDF certificate summarises the evidence in a form that remains readable outside the application.

Experimentation as Project360 capability

Project360 connected browser-side cryptographic processing, optional encryption, IPFS storage, Polygon smart-contract calls, record search, verification and certificate generation in one prototype. The work demonstrates applied Web3 understanding: technologies, dependencies, interfaces and responsibilities that must operate within one process.

From PoC to real processes

The same pattern can support intellectual-property protection, document traceability, approval steps, proof of delivery and verifiable exchange between organisations. Project360 can determine when DLT adds value, design the process, integrate existing systems and build a verifiable MVP. Production evolution then covers identity, roles, custody policies, error handling, monitoring and operational continuity.

FROM PROJECT TO INDUSTRY

IndustriesProfessional Services & E-ProcurementIndustriesAlternative Finance & FinTech
Explore the complete portfolio

Does your project have many moving parts to connect?

We start from context, dependencies and the decisions needed to build a credible path.

Let’s talk
PRIVACY / CONSENT MODE V2

We use technical storage required by the site. Google Analytics remains blocked until you choose to allow anonymous usage measurement.