A design science research framework for continuous integrity verification of electronic data capture terminals using cryptographic tamper-evident enclosure and blockchain-based certification

Authors

  • Haqi Nuha Ahnafy Bachelor's degree in veterinary medicine, Faculty of Veterinary Medicine, Universitas Airlangga, Surabaya, East Java 60115, Indonesia

DOI:

https://doi.org/10.61511/dynames.v3i1.3765

Keywords:

blockchain certification, design science research, device integrity verification, electronic data capture, physical-layer cybersecurity

Abstract

Background: The expansion of digital payment infrastructure has increased the role of Electronic Data Capture (EDC) terminals as distributed transaction endpoints in merchant environments. Existing controls include device certification, encryption, secure boot, firmware signing, anti-tamper mechanisms, and transaction monitoring. However, EDC terminals may still face post-certification integrity risks, including physical tampering, firmware reflashing, device identity spoofing, runtime manipulation, and fragmented audit evidence. This study develops NEUROSHELL as a conceptual Design Science Research (DSR) artefact for continuous integrity condition monitoring of EDC terminals. In this article, physical-layer cybersecurity refers to the protection and monitoring of the terminal enclosure, tamper status, firmware state, cryptographic device identity, and certification status, rather than to generic hardware security alone. Methods: This study used a DSR approach based on problem identification, threat modelling, design requirement derivation, artefact construction, conceptual evaluation, and validation-pathway planning. Data sources included scholarly literature, regulatory documents, technical standards, cybersecurity reports, and conceptual design materials. The framework was evaluated conceptually through comparative analysis, mapping of security objectives and stakeholder governance, and analysis of implementation feasibility. Findings: The study produced NEUROSHELL as an integrated integrity assurance framework. It combines cryptographic tamper-evident enclosure, secure boot and firmware attestation, device-bound cryptographic identity, runtime integrity proof, blockchain-based certification ledger, dashboard-based monitoring, and risk-based fail-secure response. The framework is designed to support lifecycle verification across onboarding, boot-time activation, runtime operation, firmware updates, anomaly detection, and recovery. Conclusion: NEUROSHELL shifts EDC terminal security from static certification to lifecycle-based integrity assurance, but it remains a conceptual framework that requires prototype implementation, tamper-simulation testing, latency benchmarking, false-positive analysis, and expert validation. Novelty/Originality of this article: The novelty lies in unifying physical-layer protection, firmware assurance, cryptographic identity, runtime proof, privacy-preserving blockchain certification, dashboard monitoring, and fail-secure response into a continuous integrity verification framework for EDC terminals.

References

Ankergård, S. F. J. J., Dushku, E., & Dragoni, N. (2021). State-of-the-art software-based remote attestation: Opportunities and open issues for Internet of Things. Sensors, 21(5), Article 1598. https://doi.org/10.3390/s21051598

Bank Indonesia. (2023). Bank Indonesia Annual Meeting 2023: Synergy strengthening national economic resilience and revival. https://www.bi.go.id/en/iru/highlight-news/Pages/Bank-Indonesia-Annual-Meeting-2023-Synergy-Strengthening-National-Economic-Resilience-and-Revival.aspx

Bank Indonesia. (2024). Bank Indonesia Regulation Number 2 of 2024 on information system security and cyber resilience for payment system providers, money market and foreign exchange market participants, as well as other parties regulated and supervised by Bank Indonesia. https://www.bi.go.id/en/publikasi/peraturan/Pages/PBI_022024.aspx

Bank Indonesia. (2025). Laporan Kelembagaan Bank Indonesia Triwulan III - 2025. https://www.bi.go.id/id/publikasi/laporan/Pages/LKBI-Tw.III-2025.aspx

Baskerville, R., Baiyere, A., Gregor, S., Hevner, A., & Rossi, M. (2018). Design science research contributions: Finding a balance between artifact and theory. Journal of the Association for Information Systems, 19(5), 358–376. https://doi.org/10.17705/1jais.00495

Board of Governors of the Federal Reserve System. (2023). Cybersecurity and financial system resilience report. https://www.federalreserve.gov/publications/files/cybersecurity-report-202308.pdf

CPMI-IOSCO. (2022). Implementation monitoring of the PFMI: Level 3 assessment on financial market infrastructures’ cyber resilience. https://www.iosco.org/library/pubdocs/pdf/IOSCOPD723.pdf

Delport, P. M. J., Von Solms, R., & Gerber, M. (2024). Methodological guidelines for design science research. Procedia Computer Science, 237, 195–203. https://doi.org/10.1016/j.procs.2024.05.096

European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024

European Payments Council. (2024). 2024 payments threats and fraud trends report (EPC162-24, Version 1.0). https://www.europeanpaymentscouncil.eu/

IMF. (2024). Global financial stability report, April 2024: Cyber risk: A growing concern for macrofinancial stability. https://www.imf.org/

Kuang, B., Fu, A., Susilo, W., Yu, S., & Gao, Y. (2022). A survey of remote attestation in Internet of Things: Attacks, countermeasures, and prospects. Computers & Security, 112, 102498. https://doi.org/10.1016/j.cose.2021.102498

Mullarkey, M. T., Hevner, A. R., & Ågerfalk, P. J. (2019). An elaborated action design research process model. European Journal of Information Systems, 28(1), 6–20. https://doi.org/10.1080/0960085X.2018.1451811

National Cybersecurity Center of Excellence. (2022). Validating the integrity of computing devices (NIST Special Publication 1800-34). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.1800-34

NIST. (2024a). Cybersecurity supply chain risk management practices for systems and organizations (NIST Special Publication 800-161 Revision 1, Update 1). https://doi.org/10.6028/NIST.SP.800-161r1-upd1

NIST. (2024b). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29

Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., McGuinness, L. A., Stewart, L. A., Thomas, J., Tricco, A. C., Welch, V. A., Whiting, P., & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, Article n71. https://doi.org/10.1136/bmj.n71

PCI SSC. (2024). Payment Card Industry Data Security Standard: Requirements and testing procedures, version 4.0.1. https://www.pcisecuritystandards.org/

PCI SSC. (2023). PTS Point of Interaction (POI). https://www.pcisecuritystandards.org/standards/pts-point-of-interaction-poi/

Regenscheid, A. R. (2018). Platform firmware resiliency guidelines (NIST Special Publication 800-193). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-193

Regueiro, C., & Urquizu, B. (2025). Blockchain-based evidence trustworthiness system in certification. Journal of Cybersecurity and Privacy, 5(1), Article 1. https://doi.org/10.3390/jcp5010001

Ross, R., Pillitteri, V. Y., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Volume 2, Revision 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1

Shujaa, W., Alanzi, M., & Sankaranarayanan, S. (2025). Enhancing IoT security through blockchain integration. Frontiers in Computer Science, 7, 1670473. https://doi.org/10.3389/fcomp.2025.1670473

Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339. https://doi.org/10.1016/j.jbusres.2019.07.039

Souppaya, M., Scarfone, K., & Dodson, D. (2022). Secure Software Development Framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (NIST Special Publication 800-218). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-218

Verizon. (2025). Verizon 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/

Vidaković, M., & Vinko, D. (2023). Hardware-based methods for electronic device protection against invasive and non-invasive attacks. Electronics, 12(21), Article 4507. https://doi.org/10.3390/electronics12214507

vom Brocke, J., Hevner, A., & Maedche, A. (2020). Introduction to design science research. In J. vom Brocke, A. Hevner, & A. Maedche (Eds.), Design Science Research. Cases (pp. 1–13). Springer. https://doi.org/10.1007/978-3-030-46781-4_1

Wang, W., Yan, B., Chai, B., Shen, R., Dong, A., & Yu, J. (2025). EBIAS: ECC-enabled blockchain-based identity authentication scheme for IoT device. High-Confidence Computing, 5(1), Article 100240. https://doi.org/10.1016/j.hcc.2024.100240

Yaga, D., Mell, P., Roby, N., & Scarfone, K. (2018). Blockchain technology overview (NIST Interagency/Internal Report 8202). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8202

Downloads

Published

2026-07-27

How to Cite

Ahnafy, H. N. (2026). A design science research framework for continuous integrity verification of electronic data capture terminals using cryptographic tamper-evident enclosure and blockchain-based certification. Dynamics in Engineering Systems: Innovations and Applications, 3(1), 20–39. https://doi.org/10.61511/dynames.v3i1.3765

Issue

Section

Articles

Citation Check