D-CERT: Engineering a Digital Diploma Issuance & Tamper-Proof Verification Platform via Ethereum Smart Contracts and AI RAG Assistant
Capstone Graduation Thesis for Bachelor of Engineering in Information Technology at Da Nang University of Science and Technology (DUT). This research addresses two critical challenges in educational digital transformation: guaranteeing tamper-proof academic diploma integrity using Ethereum smart contracts, and engineering an anti-hallucination AI assistant for complex university regulation retrieval with verified page citations.
EXECUTIVE RESEARCH ABSTRACT
This paper presents the architectural design, mathematical foundations, and experimental evaluation of the D-CERT platform. The system implements two novel integrations: (1) Smart contracts deployed on Ethereum Sepolia for cryptographic diploma verification using bytes32 SHA-256 digests, achieving ~65% gas savings compared to naive string storage; and (2) An academic advisor assistant utilizing Retrieval-Augmented Generation (AI RAG) with BKAI Bi-Encoder vectors, a FAISS search index (< 150ms latency), and locally hosted Qwen 2.5 14B LLM, guaranteeing zero-hallucination responses with verified page citations.
1. Problem Formulation & Research Objectives
In modern higher education, diploma verification remains largely reliant on physical parchment or centralized university databases. This paradigm suffers from three critical vulnerabilities:
- Counterfeiting & Tampering Risks: PDF scans and printed diplomas are easily manipulated with image editing software, making unauthorized credential modification undetectable by human visual inspection.
- High Verification Overhead: Employers and foreign institutions must send written inquiries to university registrars, resulting in 5 to 14 days of administrative latency for manual archive cross-referencing.
- Complexity of Academic Regulations: Students and academic staff face friction navigating graduation prerequisites and degree requirements scattered across hundreds of pages of institutional regulatory bylaws.
2. Overall Distributed System Architecture
D-CERT is engineered using a decoupled microservices architecture, establishing strict separation of concerns between client presentations, business orchestration, isolated AI vector inference microservices, and decentralized cryptographic persistence on Ethereum Sepolia.

8-Stage Pipeline Execution Breakdown:
- Stage 01: Document Hash Pipeline: Certificate PDF → SHA-256 Hash → bytes32 → Smart Contract on Ethereum Sepolia
- Stage 02: RAG Pipeline: Institutional PDF → PyMuPDF → Semantic Chunking → BKAI Bi-Encoder Embeddings → FAISS Vector Store
- Stage 03: Inference Flow: User Question → Semantic Vector Query → FAISS Retrieval → Prompt Augmentation → Qwen 2.5 14B (Ollama) → Verified Answer + Sources
3. Cryptographic & Smart Contract Subsystem
A primary engineering breakthrough of this thesis is the on-chain gas optimization strategy. Rather than storing string representations on the EVM (which consumes 80,000 to 120,000 gas per issuance), D-CERT calculates a 256-bit SHA-256 digest from the raw PDF and stores it directly as bytes32 on the Solidity smart contract.




4. AI RAG Academic Assistant
To resolve model hallucinations—a critical vulnerability when querying strict legal and academic bylaws—D-CERT employs a dual-branch Retrieval-Augmented Generation (AI RAG) architecture:
- Offline Document Ingestion: PDF bylaws are parsed with PyMuPDF, segmented into 500-token chunks with 100-token sliding overlap, transformed into semantic vector embeddings via BKAI Bi-Encoder, and cataloged into a FAISS IndexFlatL2 vector index.
- Online Semantic Inference: Upon query arrival, the query is vectorized, top-k chunks with minimum Euclidean distance are retrieved from FAISS in <150ms, structured into a grounded prompt context, and fed to local Qwen 2.5 14B under strict citation mandates.




5. Core Backend & Database Design
The Core Backend is structured under a clean 3-tier architecture (Controller, Service, Repository), ensuring modularity and unit testability. MongoDB document storage was selected for flexible schema evolution across student credentials, audit trails, and knowledge chunks.


6. Experimental Validation & Live Production Portal
The complete D-CERT system was deployed to live production environments and stress-tested with real-world credential batches, examining positive verification, cryptographic forgery detection, and full-lifecycle university registrar workflows.
6.1. Public Verification Portal



6.2. Registrar Administrative Operations







7. Benchmarks & System Evaluation
The evaluation table below summarizes empirical measurements obtained during system benchmarking and stress-testing on production infrastructure:
| Metric Dimension | Conventional Baseline | D-CERT Implementation | Improvement |
|---|---|---|---|
| On-chain Gas Consumption | ~120,000 Gas (String) | ~42,000 Gas (bytes32) | ~65% gas savings |
| Vector Similarity Retrieval | > 1,200ms (Keyword / SQL) | < 150ms (FAISS L2) | 8x faster |
| Hallucination Resistance | ~60-70% (LLM không ràng buộc) | 100% grounded with page numbers | Zero hallucination |
| Credential Verification Time | 5 – 14 days (manual) | < 2 seconds (PDF drop) | Instantaneous |
8. Conclusions & Personal Engineering Contributions
The D-CERT Capstone Thesis accomplished its engineering goals, demonstrating the architectural viability and performance gains of combining Blockchain immutability with Semantic AI RAG in higher education credentialing at Da Nang University of Science and Technology (DUT).
- ↳Authored the Graduation Thesis and architected the full system integration between Web2, AI service, and Web3
- ↳Developed the FastAPI AI microservice with FAISS and Ollama LLM integration
- ↳Authored and deployed the Solidity certificate registry contract to Sepolia testnet
- ↳Implemented the web frontend and credential lookup portal