Securing e-governance against shadow attacks with blockchain technology
Abstract
Abstract Contracts and invoices commonly utilize digitally signed PDFs to ensure content validity and integrity. These signatures enable PDF viewers to issue warnings if a document is altered after signing. However, vulnerabilities in PDF viewers have enabled a class of attacks known as shadow attacks, which undermine the integrity of digitally signed PDFs. Unlike prior attacks exploiting implementation flaws, shadow attacks leverage the flexibility of the PDF specification to embed malicious shadow documents that remain compliant with the standard. The first real-world instance of such an attack, documented under CVE-2022-25641, highlighted the inadequacy of existing defense mechanisms. This paper introduces a blockchain-based validation framework to secure PDF document exchange in e-government ecosystems. The approach integrates keyless signature infrastructure to strengthen authentication while preserving confidentiality. Experimental evaluation shows that the proposed model effectively blocks shadow-infected documents with 100% detection accuracy, while maintaining low latency (0.464–0.687 ms block creation time) and high throughput (≈100 transactions per second) in private blockchain deployments. Scalability tests confirm 95–97% detection efficiency under simulated DoS and MiTM conditions. Furthermore, integration with decentralized storage (IPFS/Filecoin) enables large-scale handling of documents up to 50 MB with negligible overhead and achieves a 30% reduction in storage costs compared to conventional PDF filtering mechanisms. Taken together, these results demonstrate that the proposed framework offers a secure, cost-efficient, and scalable foundation for enhancing digital trust in e-government services.
Article Details
Authors (2)
Priyanka Mishra
Ganesan R