Home/Labs/Tamper-Evident Ledger Lab
All 280 Labs
INTERACTIVE LAB🔐

Immutable Audit Ledger & Post-Quantum Lab (Interactive)

Tamper with a hash-chained WORM record, crypto-shred a GDPR user, and size hybrid ML-KEM handshakes live. Recomputes an append-only hash chain to localize tampering, checks the double-entry balance invariant, derives Merkle audit-path lengths, and prices PQC key growth.

Immutable Audit Ledger, Merkle Proofs & PQC

Tamper with a WORM record, crypto-shred a GDPR user, and size a hybrid post-quantum handshake against the chain.

#1 09:00:01 DEBIT $ 2500.00prev:00000000…h:afa26b7a…PII(KMS enc): 448b7cb02c…chain ok
#2 09:00:01 CREDIT $ 2500.00prev:afa26b7a…h:5c3d9e6e…PII(KMS enc): 4186fac996…chain ok
#3 09:14:22 DEBIT $ 499.00prev:5c3d9e6e…h:34ad08e0…PII(KMS enc): 4186fac996…chain ok
#4 09:14:22 CREDIT $ 499.00prev:34ad08e0…h:f9daaab9…PII(KMS enc): 448b7cb02c…chain ok
#5 10:02:57 DEBIT $ 1200.00prev:f9daaab9…h:324c98bc…PII(KMS enc): 448b7cb02c…chain ok
#6 10:02:57 CREDIT $ 1200.00prev:324c98bc…h:f2c5feb5…PII(KMS enc): cf72bf9b38…chain ok

Chain audit

VERIFIED

O(N) recompute of 6 HMAC links

Double-entry

sum = 0

debits 42.0k ¢ vs credits 42.0k ¢

Merkle audit proof

20 sibling hashes

640 B vs 268 MB log scan

TLS handshake

942 B

1 MTU fragment(s), 1.0x classical size

H_N = HMAC(seq | timestamp | payload | H_(N-1)): editing record #— breaks its hash pointer and everything downstream becomes untrusted, yet nothing can be deleted from 17a-4 WORM storage. Crypto-shredding resolves the GDPR conflict by destroying K_user in the KMS — the ciphertext stays in the chain, unreadable. Meanwhile ML-KEM/ML-DSA keys are ~100x larger, so hybrid TLS handshakes fragment across 1,500-byte MTUs.

How It Works Under the Hood

Fintech ledgers reconcile two irreconcilable mandates: SEC 17a-4 demands seven years of WORM immutability while GDPR Article 17 demands erasure. The resolution is architectural: hash-chained append-only records H_N = HMAC(payload | H_N-1) make tampering mathematically visible downstream, PII lives encrypted under per-user KMS keys so destroying the key crypto-shreds the data without breaking the chain, and Merkle trees compress audit proofs to log2(N) sibling hashes. Post-quantum migration then reintroduces physics: ML-DSA-65 signatures are ~100x larger, fragmenting TLS handshakes across MTUs.

Core Architectural Principles

  • Recomputing the chain pinpoints the first broken record and marks every downstream entry untrusted.
  • Double-entry invariant sum(debits) - sum(credits) = 0 fails instantly when a tampered amount drifts the ledger.
  • Merkle proofs ship log2(N) hashes (about 20 for a million transactions) instead of scanning the whole log.
Interview Round Script

In any payments or wallet design, state the ledger invariants up front: append-only, double-entry balanced, reversal transactions instead of updates. Then layer tamper-evidence (hash chains plus Merkle-anchored roots) and reconcile GDPR against WORM with crypto-shredding, which interviewers treat as a senior signal. Close by mentioning hybrid X25519 + ML-KEM against harvest-now-decrypt-later.

Key Trade-Offs

Immutable hash-chained ledgers guarantee tamper-evidence and regulatory auditability, but never shrink, complicate erasure until crypto-shredding, and inflate bandwidth under post-quantum suites.

Related Curriculum Chapter

Compliance, Immutable Audit Trails & Post-Quantum Cryptographic Systems

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs