Making diplomas tamper-proof with blockchain

Designing and deploying UDoCert: the University of Douala issues digital diplomas that any employer can verify in seconds, using the open Blockcerts standard.

Problem
Let anyone verify a diploma instantly, without relying on a trusted third party, while staying simple for university staff to operate.
Role
Blockchain project lead (final-year internship)
Period
Feb. – Jul. 2025
Sector
Higher education · Public sector
Result
6 months from scoping to AWS deployment

Fig. 1Université de Douala

The lifecycle of a certified diploma

Click a step

The university generates the digital diploma in the open Blockcerts format: a JSON file holding the graduate’s identity, the degree and the institution’s signature.

UDoCert architecture, Blockcerts v3 standard.

01Context

Like many universities, the University of Douala faces diploma fraud. Verifying a diploma relied on manual exchanges: slow for employers, costly for the administration.

02Challenge

Let anyone verify a diploma instantly, without relying on a trusted third party, while staying simple for university staff to operate.

03Approach

  1. Choose the right standard

    Comparing digital credentialing approaches; choosing Blockcerts v3, the open standard from the MIT Media Lab.

  2. Design the certification chain

    Diploma issuance, hashing, anchoring on the Bitcoin blockchain (Testnet), public verification.

  3. Deploy controlled infrastructure

    Docker containers, Nginx reverse proxy, hosting on AWS EC2.

  4. Document and hand over

    Final-year thesis and presentation of the technical results to the CDNU teams.

04Deliverables

  • Working issuance and verification prototype
  • Containerised infrastructure deployed on AWS
  • Technical documentation and thesis

Tools

  • Blockcerts v3
  • Bitcoin Testnet
  • JavaScript
  • Docker
  • Nginx
  • AWS EC2

05Results and measurement

ValueIndicatorScope and method
6months from scoping to AWS deploymentFebruary to July 2025, final-year internship. I led the project and handled the deployment.

06What I took away

The technology was the easy part. The real subject was trust: who issues, who verifies, and how to explain a cryptographic proof to a recruiter in plain words.

Source code on GitHub