Inspiration

Indonesia has 4,700+ higher education institutions reporting to PDDikti every semester. These reports determine whether a diploma is valid, whether a student receives KIP Kuliah scholarships, and whether a graduate passes civil servant verification. Yet 639,000 students remain unreported as of April 2026 — most without knowing it until they're rejected by SSCASN or recruiters.

Worse, there's no way to compare what campuses show students versus what they report to the state. Scandals keep erupting: 216 Law Faculty students at Tadulako caught in grade trading, a Rector and Vice Rector at Unsoed arrested for selling admission seats at Rp 500 million each, and 45% of students admitting to thesis data manipulation. Meanwhile, SIVIL only verifies whether a diploma exists — not whether the grades behind it are real.

We asked: what if the campus and the state had to independently sign off on the same dataset, and the result was immutably recorded for anyone to verify?

What it does

ELISE (Academic Information System Desensitization) adds a dual attestation layer on top of existing reporting obligations:

  1. Campus commits — When a semester dataset is locked and sent to Neo Feeder, a Merkle tree is built and its root is recorded on-chain as R_campus.
  2. PDDikti attests — The state independently computes the root from received records and records R_state.
  3. Automatic status — If R_campus == R_state, status is ALIGNED. If not, it's DISCREPANCY — visible to regulators instantly.
  4. Student proof — Students get a Merkle proof (QR code) showing their grade exists in the state-recognized report. Verifiers validate it on-chain without login or database access.
  5. AI watchdog — Anomaly scoring detects repeated DISCREPANCY, late submissions, and mass revisions before graduation. Claude writes narrative summaries for regulators.

No personal data ever touches the ledger — only cryptographic hashes. No additional work for campuses — the system reads the same dataset already sent to Neo Feeder.

How we built it

Frontend: Next.js 14 (App Router), TypeScript, TailwindCSS, shadcn/ui, viem for on-chain reads, QR code generation.

Backend: Next.js Route Handlers, Prisma ORM, PostgreSQL for off-chain data (grades, transcripts, revision history — encrypted, never sent to ledger).

Smart Contract: Solidity 0.8.x deployed on Base Sepolia using Foundry. AcademicAnchor contract with AccessControl (ISSUER per campus, AUTHORITY for PDDikti attester) and Pausable. Functions: commitRoot, attestRoot, status, history, verify. OpenZeppelin libraries.

Attester Node: Separate Node.js service with its own key pair — receives dataset via API, recomputes Merkle root independently, calls attestRoot. This makes dual attestation real: two separate services, two separate keys.

Merkle Tree: Built with @openzeppelin/merkle-tree. Each leaf hashes a student's grade record. The root is what goes on-chain. Proofs are compressed JSON in QR codes.

AI Module: Z-score anomaly calculation on reporting patterns (DISCREPANCY frequency, late commits, grade spikes per lecturer). Claude API generates Indonesian-language narrative summaries and recommendations for LLDIKTI.

Deployment: Vercel (frontend + API + attester), Neon/Supabase (PostgreSQL), Base Sepolia (testnet).

Challenges we ran into

  • Dual key management: Making dual attestation actually work meant running the campus backend and attester node on completely separate services with different keys. Getting the architecture right so neither could impersonate the other took careful design.

  • Merkle proof UX: Making proofs accessible to students who have zero Web3 knowledge. We went with compressed JSON in QR codes — no wallet needed, no MetaMask, no seed phrase. Just scan and verify.

  • Privacy vs transparency tradeoff: We needed to prove data integrity without exposing personal data. Hashing without PII (no name, no NIM, no NIK in the hash input) was the solution, but ensuring the hash was still meaningful for verification required careful record structuring.

  • Simulating PDDikti convincingly: The attester node had to genuinely recompute hashes, not just be a button that says "approve." We built it as a real independent service that fetches the dataset and processes it from scratch.

  • 24-hour time constraint: Building a full-stack Web3 application with smart contract deployment, two backend services, database, AI integration, and a polished frontend in 24 hours was intense.

Accomplishments that we're proud of

  • End-to-end dual attestation on testnet — campus commits, PDDikti attests, status computed automatically, student proof generated and verified. Fully functional.
  • Zero personal data on-chain — Privacy-first by design. Only Merkle roots touch the ledger.
  • Invisible Web3 — Students and lecturers interact through email/NIM login. Wallets are created automatically. No crypto UX friction.
  • Real independent attester — Not a mock. A separate service with its own keys that genuinely recomputes the dataset.
  • AI anomaly detection — Deterministic z-score calculation with LLM-generated narrative summaries, ready for regulatory dashboards.
  • Comprehensive proposal — Full English documentation covering problem statement, solution architecture, tech stack, risk mitigation, and adoption roadmap.

What we learned

  • Web3 shines when trust is distributed — The moment you need two parties (campus and state) to independently agree on something, and neither should be able to unilaterally alter it, blockchain becomes the obvious answer.
  • "Invisible Web3" is the only Web3 that works at scale — If end users need to understand wallets, gas fees, or seed phrases, adoption dies. Embedded wallets and email login are non-negotiable.
  • Dual attestation is powerful but underused — The pattern of two independent parties signing the same data and comparing results has applications far beyond education: healthcare records, supply chain, government procurement.
  • Regulatory alignment matters more than tech novelty — ELISE works because it layers on top of existing obligations (Permenristekdikti 61/2016, Perpres 82/2023). No new laws needed.
  • Indonesia's data privacy landscape is urgent — 119.5 million records breached, zero PDP derivative regulations issued. Academic data integrity is not theoretical — it's a crisis.

What's next for ELISE

  • Pilot with one campus and regional LLDIKTI — Run for one full semester, demonstrate ALIGNED status to students and regulators.
  • Official PDDikti attester integration — Move from simulated to production attester operated by LLDIKTI on received Feeder data.
  • BKN and KIP Kuliah modules — Let civil servant verification and scholarship disbursement validate against on-chain roots instead of uploaded PDFs.
  • W3C Verifiable Credentials — Issue EBSI-compatible credentials for cross-border diploma verification.
  • Consortium ledger — Scale from Base Sepolia to a permissioned Hyperledger Besu network with periodic anchoring to public L2.
  • K-12 extension — Apply the same dual attestation pattern to Dapodik for high school diplomas and NISN verification.

Built With

Share this project:

Updates

Submission history