Securing Educational Financial Data Against Insider Threats: A Hybrid Blockchain Approach with Merkle Tree Aggregation

Authors

  • Adi Alfian Hafis Universitas Semarang, Indonesia
  • Soiful Hadi Universitas Semarang, Indonesia
Pages Icon

DOI:

https://doi.org/10.63158/journalisi.v8i4.1719

Keywords:

Hybrid Blockchain, Merkle Tree Aggregation, Insider Threats, Insider Threat Detection, Tamper-Evident Logging, Reversal Entry, Smart Contract

Abstract

Financial information systems in educational institutions face insider threats where privileged administrators can manipulate database records undetected by conventional security. This study proposes a Hybrid Blockchain architecture integrating Merkle Tree Aggregation and a Reversal Entry mechanism to establish a tamper-evident financial audit trail and address these data integrity gaps. Developed via the Design Science Research Methodology (DSRM), the system implements three cryptographic layers: a SHA-256 Recursive Transaction Hash Chain for local integrity, a Keccak-256 Merkle Tree for daily aggregation, and public Ethereum anchoring. Empirical evaluations demonstrate successful cryptographic integrity verification across all five database manipulation attack scenarios with zero false positives only under the five tested normal operational scenarios, relying strictly on deterministic hashing rather than AI-based anomaly detection. Computational latency remains consistent at 3.45 ms per transaction. Based on Sepolia testnet data under mainnet-equivalent projections, the 1,000:1 aggregation compression yields 99.90% cost efficiency compared to pure public blockchains, with sensitivity analysis confirming financial viability across volatile gas prices and exchange rates. These findings indicate the technical and economic feasibility of adopting a Hybrid Blockchain for detecting tampering and preserving data integrity in educational institutional financial data under the evaluated scenario.

Downloads

Download data is not yet available.

References

[1] M. A. Almaiah, L. M. Saqr, L. A. Al-rawwash, L. A. Altellawi, R. Al-ali, and O. Almomani, “Classification of Cybersecurity Threats, Vulnerabilities and Countermeasures in Database Systems,” Comput. Mater. Contin., vol. 81, no. 2, pp. 3189–3220, 2024, doi: 10.32604/cmc.2024.057673.

[2] A. Al-harrasi, A. K. Shaikh, and A. Al-badi, “Towards protecting organisations’ data by preventing data theft by malicious insiders,” Int. J. Organ. Anal., vol. 31, no. 3, pp. 875–888, 2023, doi: 10.1108/IJOA-01-2021-2598.

[3] A. R. Marbut and P. D. Harms, “Fiends and Fools: A Narrative Review and Neo‑ socioanalytic Perspective on Personality and Insider Threats,” J. Bus. Psychol., vol. 39, no. 3, pp. 679–696, 2024, doi: 10.1007/s10869-023-09885-9.

[4] R. Zhao, M. Shoaib, V. T. Hoang, and W. U. Hassan, “Rethinking tamper-evident logging: A high-performance, co-designed auditing system,” in Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, Taipei: Association for Computing Machinery, 2025, pp. 2624–2638, doi: 10.1145/3719027.3765024.

[5] R. Biswas, S. Jana, M. Pal, D. Chatterjee, K. Pal, and P. Dhar, “Data Integrity and Security Mechanisms in Cloud-Based Relational Databases,” Int. J. Adv. Res. Sci. Commun. Technol., vol. 4, no. 6, pp. 399–405, 2024, doi: 10.48175/IJARSCT-22561.

[6] M. M. Khan, F. S. Khan, M. Nadeem, T. H. Khan, S. Haider, and D. Daas, “Scalability and efficiency analysis of hyperledger fabric and private Ethereum in smart contract execution,” Computers, vol. 14, no. 4, p. 132, 2025, doi: 10.3390/computers14040132.

[7] P. Shylaja and J. S. Jayasudha, “A Comprehensive Review of Blockchain and Smart Contracts: Foundations, Applications, and Technical Challenges,” Prem. J. Sci., vol. 15, p. 100257, 2026, doi: 10.70389/PJS.100257.

[8] E. Alaka, K. Abiodun, S. O. Jinadu, E. Igba, and V. N. Ezeh, “Data Integrity in Decentralized Financial Systems: A Model for Auditable, Automated Reconciliation Using Blockchain and AI,” Int. J. Manag. Commer. Innov., vol. 13, no. 1, pp. 136–158, 2025, doi: 10.5281/zenodo.15753099.

[9] J. Westphall and J. E. Martina, “Blockchain Privacy and Scalability in a Decentralized Validated Energy Trading Context with Hyperledger Fabric,” Sensors, vol. 22, no. 12, p. 4585, 2022, doi: 10.3390/s22124585.

[10] S. Hadi, A. N. Putri, and P. A. Buana, “Selecting Achievement-Based Students Using Blockchain and AHP: Semarang University Case Study,” J. Inf. Syst. Informatics, vol. 6, no. 4, pp. 2192–2206, 2024, doi: 10.51519/journalisi.v6i4.901.

[11] E. M. Alotaibi, H. Issa, and M. Codesso, “Blockchain-based conceptual model for enhanced transparency in government records: a design science research approach,” Int. J. Inf. Manag. Data Insights, vol. 5, no. 1, p. 100304, 2025, doi: 10.1016/j.jjimei.2024.100304.

[12] F. Wen, “A Design Science Study of a Mobile Human Resource System for Internal Staffing and User Acceptance,” J. Cases Inf. Technol., vol. 27, no. 1, pp. 1–29, 2025, doi: 10.4018/JCIT.389148.

[13] K. Yeh, G. Yang, C. Butpheng, L. Lee, and Y. Liu, “A Secure Interoperability Management Scheme for Cross-Blockchain Transactions,” Symmetry (Basel), vol. 14, no. 12, p. 2473, 2022, doi: 10.3390/sym14122473.

[14] G. Mandinyenya and V. Malele, “A Hybrid Framework for Enhancing Privacy in Blockchain-Based Personal Data Sharing using Off-Chain Storage and Zero-Knowledge Proofs,” J. Inf. Syst. Informatics, vol. 7, no. 2, pp. 1977–2005, 2025, doi: 10.51519/journalisi.v7i2.1119.

[15] S. V. K. Gummadi, “Recursive Transaction Hash Chains for Immutable Audit Trails in Mortgage Platforms,” Int. J. Emerg. Trends Comput. Sci. Inf. Technol., vol. 6, no. 4, pp. 49–54, 2025, doi: 10.63282/3050-9246.IJETCSIT-V6I4P107.

[16] L. Wei, F. Al-rashidi, and A. Krishnamurthy, “ChainGuard: A Blockchain- and IoT-Augmented Framework for Real-Time Database Integrity Assurance in Distributed Healthcare Information Systems,” DATAMIND, vol. 4, no. 1, pp. 6–24, 2026, doi: 10.63646/datamind.2026.040102.

[17] N. R. Reddy, S. Suryadevara, and K. G. R. Reddy, “Quantum secured blockchain framework for enhancing post quantum data security,” Sci. Rep., vol. 15, no. 1, p. 31048, 2025, doi: 10.1038/s41598-025-16315-8.

[18] P. Dhiman, S. K. Henge, S. Singh, A. Kaur, P. Singh, and M. Hadabou, “Blockchain Merkle-Tree Ethereum Approach in Enterprise Multitenant Cloud Environment,” Comput. Mater. Contin., vol. 74, no. 2, pp. 3297–3313, 2023, doi: 10.32604/cmc.2023.030558.

[19] J. P. Lemayian, G. Gagnon, K. Zhang, and P. Giard, “HardVault: A Hybrid FPGA-Based Ethereum-Bitcoin Cold Wallet,” IEEE Trans. Very Large Scale Integr. Syst., 2026, doi: 10.1109/TVLSI.2026.3696577.

[20] A. S. Paramita and M. Tarigan, “Analysis of Gas Fee Patterns in Blockchain Transactions - A Case Study on Ethereum Smart Contracts,” J. Curr. Res. Blockchain, vol. 2, no. 3, pp. 180–189, 2025, doi: 10.47738/jcrb.v2i3.41.

[21] C. F. Ikenga-Metuh and A. Yeboah-Ofori, “Blockchain security using confidentiality, integrity, and availability for secure communication,” Blockchains, vol. 4, no. 1, p. 3, 2026, doi: 10.3390/blockchains4010003.

[22] O. Kuznetsov, A. Rusnak, A. Yezhov, K. Kuznetsova, D. Kanonik, and O. Domin, “Merkle trees in blockchain: A Study of collision probability and security implications,” Internet of Things, vol. 26, p. 101193, 2024, doi: 10.1016/j.iot.2024.101193.

[23] C. Regueiro, I. Seco, B. Urquizu, and J. Mansell, “A Blockchain-Based Audit Trail Mechanism: Design and Implementation,” Algorithms, vol. 14, no. 12, p. 341, 2021, doi: 10.3390/a14120341.

[24] W. Liu, J. Li, and N. Chen, “CBAATM: A Blockchain-AI Integrated Framework for Real-Time Anomaly Detection and Compliance Verification in Smart Accounting Information Systems,” Informatica, vol. 49, no. 20, pp. 253–272, 2025, doi: 10.31449/inf.v49i20.10028.

[25] F. Khan and S. Chadni, “Digital Ledger Optimization Techniques for Enhancing Transaction Speed and Reporting Accuracy in Accounting,” Am. J. Sch. Res. Innov., vol. 1, no. 02, pp. 171–222, 2022, doi: 10.63125/33t06k57.

[26] U. Rauf, F. Mohsen, and Z. Wei, “A Taxonomic Classification of Insider Threats: Existing Techniques, Future Directions & Recommendations,” J. Cyber Secur. Mobil., vol. 12, no. 2, pp. 221–252, 2023, doi: 10.13052/jcsm2245-1439.1225.

[27] I. U. Akpara and O. V. Bamigwojo, “Secure Database Trigger and Stored-Procedure Design for Automated Compliance Logging in Multi-User Administrative Systems,” Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol., vol. 9, no. 3, pp. 974–999, 2023, doi: 10.32628/CSEIT25112793.

[28] B. Wang, R. Jiang, X. Pu, and H. Zhang, “An on-chain and off-chain collaborative data sharing and access control model for electronic medical records,” J. Supercomput., vol. 81, no. 2, p. 396, 2025, doi: 10.1007/s11227-024-06884-2.

[29] H. Su, S. Dong, and T. Zhang, “A Hybrid Blockchain-Based Privacy-Preserving Authentication Scheme for Vehicular Ad Hoc Networks,” IEEE Trans. Veh. Technol., vol. 73, no. 11, pp. 17059–17072, 2024, doi: 10.1109/TVT.2024.3424786.

[30] S. Van Damme et al., “Impact of Latency on QoE, Performance, and Collaboration in Interactive Multi-User Virtual Reality,” Appl. Sci., vol. 14, no. 6, p. 2290, 2024, doi: 10.3390/app14062290.

[31] K. Somei, K. Oshima, and T. Tsumugiwa, “Effects of Display Response Latency on Brain Activity During Device Operation,” IEEE Access, vol. 11, pp. 34860–34869, 2023, doi: 10.1109/ACCESS.2023.3262658.

[32] S. Porkodi and D. Kesavaraja, “Escalating Gas Cost Optimization in Smart Contract,” Wirel. Pers. Commun., vol. 136, no. 1, pp. 35–59, 2024, doi: 10.1007/s11277-024-11066-7.

[33] J. Seol, J. Deuja, I. N. Park, C. Pu, and N. Park, “A Quantitative Study across CIA (Confidentiality, Integrity, Availability) Triad and Performance in Blockchain-Based Crypto-Space,” in 2025 7th International Conference on Blockchain Computing and Applications (BCCA), Dubrovnik, Croatia, 2025, pp. 161–168, doi: 10.1109/BCCA66705.2025.11229817.

Downloads

Published

2026-08-22

Issue

Section

Articles

Most read articles by the same author(s)