Are We Ready for Another Change? Digital Signatures Can Change How We Handle the Academic Record.

Thomas C. Black, John W. Mohr · College and university · 2004

In this electronic age, where information is digital and service is virtual, the registrar profession is changing rapidly to keep up with increasing standards and expectations. Our mission is becoming one of enabling self-service as opposed to one of providing direct service to our constituencies. Over the last decade our production of official transcripts had not changed that much-until just recently. EDI and now XML standards enable system-to-system exchanges of academic records information. While many of us display student academic records under secure access to our students using the World Wide Web, as a time-honored rule, official transcripts are still printed. Through PKI (public key infrastructure), paper's dominance as the medium and means for producing official transcripts may be over. What do people want or need in official documents like the transcript? Confidence. That is, they want to know that the information contained in the official document is true and accurate, and prepared and delivered in a manner that assures them that the document was not altered from its original form. Accordingly, registrars secure our information systems from unauthorized breaches, and we direct printing of academic information on special paper, on designated and restricted printers. Some of us further stamp or seal transcript documents before they are posted and delivered by secure carrier, usually the U.S. Postal Service. However, PKI affords us the sumo confidence but in electronic form. Utilizing Public Key Infrastructure (PKI) Through the use of PKI technology and infrastructure, information may retain its digital form and offer the recipient the same assurance that the document is as authentic as one received in the mail. PKI technology enables the placement of an electronic signature on a digital file (substituting for the special paper, the seal, and secure posting of the paper document), which assures the recipient that the digital file has not been altered and originates from a verifiable party. Let's suppose instead of directing transcript information to a printer, you send it to Adobe's Acrobat print driver and produce a PDF (portable document format) file. This common, but proprietary, file format has become a trusted and de facto standard for presenting documents of all types. You certify the contents of the PDF file by attaching an electronic signature that will remain with the file as long as the original is not altered. By verifying the provenance of the electronic signature-the PDF transcript-the recipient is assured of the authenticity of the document, regardless of whether the file was sent directly from the institution, the student, or even another third party. In other words, the signed file is self-certifying. To operationalize this concept or practice, institutions will likely leverage their online information services for students, and present or revise-if they already have such a system-a transcript ordering system. The student will authenticate him or herself to the registrar's secure transcript system using a known user ID and password. For the University of Chicago, this is the user's Cnetid and Cnet password. (This authentication uses industry standard 128-bit SSL encryption to query an LDAP directory containing the student's access credentials.) This identifier is required for use of the e-mail system as well as the student academic portal, and is used by the student during his or her time at the University. As a result, the student will be familiar with the identifier and not have any difficulty accessing the system. Once authenticated, a report will be created containing the academic information for that student. This information will be compiled from the Student System. The secure transcript application server will use the student information to create a digitally signed document that is delivered to the end user either within the Web browser as part of a secure session (using SSL), or as a file that can be down-loaded to the student's computer. …

Read the paper · More papers on PaperTik