Managing Student Identities in the Digital Era: Technologies like Single Sign-On Are Convenient, but Do They Compromise the Security and Privacy of Students' Data?

Marie Bjerede · T.H.E. Journal Technological Horizons in Education · 2015

[ILLUSTRATION OMITTED] THE DIGITAL LEAP is at a tipping point. School districts nationwide are rapidly turning to digital learning content from websites and apps, according to Consortium for School Networking's report Identity and Access Management: Fundamentals for Securing Student Data and Privacy. According to report Seven Keys to Unlocking School Transformation with Digital Media, this move is inspired by the power of digital media to engage students in learning that is relevant to them in classroom and beyond. In fact, CoSN's 2015 K-12 IT Leadership Survey finds that district technology leaders expect that at least 50 percent of instructional materials will be digital within three years. Unless districts manage students' access to online resources, digital leap could slow to a crawl. Robust identity and access-management technologies should go hand-in-hand with shift to digital content. These technologies can provide several benefits: * Instructional value with safe, secure and efficient access to digital content; * improved risk management with password security and heightened control of student data; * automation and efficiency with consolidated user accounts and access routes to digital content; and * transparency for parents who want to know how student information is used. There are two areas of concern, however. The first challenge teachers and students face is managing and remembering logins and passwords for a large number of applications. The second issue is students' release of power to third party software, enabling software to take actions such as sending e-mails on students' behalf. Provisioning Access and Data Sharing Securing students' data and privacy is becoming more complicated, as districts contract with cloud service providers for access to digital content. Educators must carefully consider how they provide access rights to online content and share student data within and beyond district. They must ask questions such as: * What can users access online and what are they allowed to do? * How will digital resources be managed to provide required access? * What data about students is shared? * Who decides what is shared? * How is data sharing controlled? A third-grader could sign on to an LMS with a username and password, giving her access to grade-appropriate or classroom-specific digital learning resources. An English language learner might have access to a different set of resources to support learning. A 12th-grader signing on to same LMS might be able to access more advanced content. Meanwhile, a teacher would have greater access privileges to instructional and administrative resources, such as diagnostic tools, lesson plans and gradebooks. Districts release user attributes--age, grade level and learning needs of students; roles and responsibilities of teachers--to LMS to manage appropriate access. The LMS, like many websites and apps, might provide access to content from multiple providers. Using their authenticated user ID and password, students can log in to one website and then click into many other websites and apps without any further authentication. This is known as federated identity management--multiple providers agree to allow with one set of credentials for each user. Single sign-on is convenient--and can put incredible learning resources at students' fingertips. Without adequate controls, however, single sign-on can leave student data vulnerable. Jim Siegl, technology architect of Fairfax County Public Schools (VA), explained a common type of authorization that users are asked to provide to apps and software services. I use this analogy with my instructional colleagues and it's a revelation for them. A driver's license is an example of a federated credential. …

Read the paper · More papers on PaperTik