DOI: 10.3390/electronics15153478 ISSN: 2079-9292

A Kubernetes-Deployed Tamper-Evident Media-Evidence Provenance Pipeline with Hybrid Blockchain/IPFS Anchoring and Queue-Mediated Ingress

Haoliang Wang, Zarina Shukur, Khairul Akram Zainol Ariffin, Lili Wang

High-stakes online assessment produces suspicious-event records, yet storage placement and burst admission remain insufficiently characterized. This article presents a Kubernetes-deployed provenance pipeline integrating Hyperledger Fabric, IPFS, SHA-256 verification, and RabbitMQ ingress. Media objects are retained in IPFS, while compact semantics, CIDs, and verification anchors are committed to Fabric. At 5 TPS, five 300-transaction runs completed under both direct large-payload and compact-anchor ledger conditions. At 20 TPS, compact anchoring of a pre-retained IPFS object sustained 19.40 ± 0.00 TPS with 0.22 ± 0.00 s mean ledger latency; direct large-payload submission achieved 14.20 ± 0.40 TPS with 31.62 ± 3.35 s latency. A write-load sweep identified 100 TPS as the transition point; higher loads were delay-dominated. Three 1000-VU PTS runs reduced mean response time from 4.76 ± 0.78 s to 2.40 ± 0.02 s, with similar failure rates. In three 30-message consumer-enabled runs, all 90 messages reached IPFS retention, Fabric commit, query visibility, and manual acknowledgement without retry, producer failure, or dead-letter outcome. Mean queue-drain and total completion times were 61.80 ± 0.71 s and 62.99 ± 0.15 s. The results isolate Fabric transaction-path payload cost and distinguish queue acceptance from downstream completion.

More from our Archive