In a port logistics environment, numerous participants interact while containers and related events flow among them. To enable reliable tracking of these activities, a Blockchain-based solution can be employed. A Permissionless Blockchain is not suitable in this context, as participant identities are typically anonymous. Instead, a Permissioned Blockchain is more appropriate, since each participant operates with a well-defined and verifiable identity. In this work, the selected implementation of a Permissioned Blockchain is the open-source platform Hyperledger Fabric (HLF). The HLF network instance builds upon an existing Platform that leverages HLF’s Private Collections feature in combination with a distributed access control list to restrict access to specific data and events. Furthermore, to enhance confidentiality, privacy, and trust, a Confidential Computing technique has been integrated into HLF. Specifically, I employed Intel Software Guard Extensions (SGX), which ensures that only authorized entities can access plaintext data, even at the hardware level. SGX protects sensitive information stored in memory—and also files on the filesystem, including the Blockchain itself—by isolating them within protected memory areas known as “enclaves”. These enclaves prevent unauthorized access from other users, processes, privileged system components, or even the hypervisor. Additionally, SGX provides a Remote Attestation mechanism that enables an enclave to prove to another enclave or to a traditional application that it is executing specific code within an SGX environment. This mechanism makes it possible for a member of the HLF network to securely share data or events with an external entity whose identity may not be known in advance.
Confidential and Permissioned Blockchains for the logistics domain
AVOLA, STEFANO
2026-07-28
Abstract
In a port logistics environment, numerous participants interact while containers and related events flow among them. To enable reliable tracking of these activities, a Blockchain-based solution can be employed. A Permissionless Blockchain is not suitable in this context, as participant identities are typically anonymous. Instead, a Permissioned Blockchain is more appropriate, since each participant operates with a well-defined and verifiable identity. In this work, the selected implementation of a Permissioned Blockchain is the open-source platform Hyperledger Fabric (HLF). The HLF network instance builds upon an existing Platform that leverages HLF’s Private Collections feature in combination with a distributed access control list to restrict access to specific data and events. Furthermore, to enhance confidentiality, privacy, and trust, a Confidential Computing technique has been integrated into HLF. Specifically, I employed Intel Software Guard Extensions (SGX), which ensures that only authorized entities can access plaintext data, even at the hardware level. SGX protects sensitive information stored in memory—and also files on the filesystem, including the Blockchain itself—by isolating them within protected memory areas known as “enclaves”. These enclaves prevent unauthorized access from other users, processes, privileged system components, or even the hypervisor. Additionally, SGX provides a Remote Attestation mechanism that enables an enclave to prove to another enclave or to a traditional application that it is executing specific code within an SGX environment. This mechanism makes it possible for a member of the HLF network to securely share data or events with an external entity whose identity may not be known in advance.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



