Introduction
The key facet of any profession is the recognition and enforcement of a standard set of ethical practices (Seels & Richey, 1994). The codification and vigorous enforcement of professional ethics promoted by Finn (1953); the six criteria of professional ethics were adopted to establish the current code of ethics for the Association for Educational Communications and Technology. Due to rapid changes in technology, ethical norms are also being changed, confronting the educational industry with far-reaching issues (Seels & Richey, 1994). Change in educational technology has been accompanied by new attitudes on academic integrity. New technology brings new topics (Seels & Richey, 1994), such as computer based duplication, copyright laws, activities of computer hackers’ technologies for gaining illegal entry into databases, and creating and disseminating computer viruses. “These issues are being addressed in the courts, as well as in codes of ethics” (p. 107). The topic of academic integrity ranks high.
CDMP, CBIP, MSc, 6970 NW 186th Street, #211, Miami, FL 33015. Telephone: (305) 394-7632.
CDMP, CBIP, MSc, 6970 NW 186th Street, #211, Miami, FL 33015. Telephone: (305) 394-7632.
Academic Integrity
Lambert and Hogan (2004) noted that academic integrity is of grave concern and epidemic across most college campuses. Stronger forms of authentication emerge to offset this crisis. Currently, collaborations between academia and the business sector are finding innovations in authentication that can be implemented to ascertain “who’s who in distance education.” However, far fewer studies have been undertaken for online academic integrity than for traditional learning. Lanier (2006) attempts to compensate when investigating several studies that address both traditional and online academic integrity. Lanier reported that a study of 1,262 students at a large, state-funded university found a high level of academic dishonesty in online courses.
Validation for Authentication
Legislation: HEA 2008
Bailie and Jortberg (2008) define authentication as validation the entity offering the identification token is actually the one assigned to use it. The question then to consider; is academic integrity a veracity, conjecture, or is there legitimate requisite to invest in more robust, more sophisticated authentication? The Higher Education Act (HEA) of 1965 was reauthorized in 2008, in response to General Accounting Office testimony before the Senate Committee on Health, Education, Labor, and Pensions to prevent fraud in Title IV programs:
Specifically, the College Opportunity and Affordability Act (H.R. 4137), which was passed by the Committee on Education and Labor in the U.S. House of Representatives on November 15, 2007, corresponds with a bill passed by the U.S. Senate (S. 1642) in July 2007. Both pieces of legislation contain verbiage directing accreditation agencies to “require an institution that offers distance education to have processes through which the institution establishes that the student who registers in a distance education course or program is the same student who participates in and completes the program and receives the academic credit.” (H.R. 4137, 110th Congress, 2007)
The Joint Conference Committee of Congress and the U.S. Department of Education have confirmed; initially institutions may use simple efforts already in place at most institutions to verify identity (Bailie & Jortberg, 2008). Contrary to expectations, most institutions found they need only “verify the identity of a student who participates in class or coursework” by using, at the discretion of the institution, methods such as:
A secure login and pass code;
Proctored examinations; and
New or other technologies and practices that are effective in verifying student identification (Bart, 2009).
Consequently, most institutions were already in compliance. Nevertheless, compliance was just the instigation, as attention to authentication continues to affect sober trepidation.
Features of Authentication
Since 1996, National American University (NAU) has provided a virtual campus to its growing population of students (Bailie & Jortberg, 2008). NAU partnered with Acxiom Corporation, report the authors, to enlist a user verification strategy, consisting of four crucial features for managing a secure system: identification, authentication, authorization, and accountability (IAAA). IAAA is defined as follows:
Identification—the initial establishment of an individual’s factual identity.
Authentication—the validation that the entity offering the identification token is actually the one assigned to use it.
Authorization—the certainty that the entity is granted access only to areas where he/she has been bestowed proper privilege or authority.
Accountability—the assurance that only authorized entities have accessed the secure system.
Accountability is achieved when proper identification, authentication, and authorization has been accomplished (Bailie & Jortberg, as cited in Bruhn, Gettes, & West, 2003).
Authentication Technology
Secureexam
Simonson, Smaldino, Albright, and Zvacek (2009) indicated Secureexam is one brand of “cheat proofing” software with features such as: fingerprint analysis, voice recognition, and video surveillance; however, they also suggest third party test proctors offer a reasonable element of accountability and offset the “insecurity” of the online environment. As the audiences for distance education institutions and programs vary in complexity, their respective needs for authentication technology may be just as diverse and necessitates the need for authentication technology to persist.
Out-of-Wallet
Technology for fraud mitigation has matured in sophistication, coining new phrases like data forensics. In their pilot (Bailie & Jortberg, 2008), NAU and Acxiom identified four main premises for identity authentication:
Who we are—fingerprints, iris scans, voice recognition, DNA, and so on;
What we have—birth certificate, driver’s license, passport, digital tokens, and so on;
What we know—in-wallet and out-of-wallet information about our past, such as financial, geographical, and demographic data.
Where we are at a specific moment in time—video monitoring, IP address, telephone access, and so on.
In an endeavor to secure its testing procedure through data forensics, NAU sought to capitalize on the massive collection of data at Acxiom compiled for use with banking authentication’s familiar challenge questions (Bailie & Jortberg, 2008). Acxiom researched the distance education domain using ten types of online learning assessments defined by Illinois Community Colleges (Bailie & Jortberg, 2009) (see Table 1).
Challenge questions is a method banks use to access or reset a forgotten password. In a pilot program, NAU and Acxiom merged a two-tier process for authentication: (1) on the university level users login to a learner management system (LMS), such as Blackboard, in the traditional manner; (2) for examinations, the system switches to the Acxiom environment where “out-of-wallet” historical data, stored in Acxiom’s database is presented for second level testing authentication questions (Bailie & Jortberg, 2008). When a learner is asked what street he or she grew up on—A, B, C, D, or E—they will likely be the only person who can respond accurately. They are then authenticated out-of-wallet for the exam. Out-of-wallet authentication is the method frequently used by financial institutions:
Types of Online Learning Assessments
| Responses | Frequency | Percent |
|---|---|---|
| Homework assignments | 655 | 20 |
| Online tests and/or quizzes | 606 | 19 |
| Bulletin-board postings | 547 | 17 |
| Projects/papers | 494 | 15 |
| Participation in chat room | 313 | 10 |
| Proctored tests and/or quizzes | 234 | 7 |
| Team projects | 149 | 5 |
| Reflective journal | 92 | 3 |
| Student portfolio | 79 | 2 |
| Other | 31 | 1 |
| Total | 3,200 |
| Responses | Frequency | Percent |
|---|---|---|
| Homework assignments | 655 | 20 |
| Online tests and/or quizzes | 606 | 19 |
| Bulletin-board postings | 547 | 17 |
| Projects/papers | 494 | 15 |
| Participation in chat room | 313 | 10 |
| Proctored tests and/or quizzes | 234 | 7 |
| Team projects | 149 | 5 |
| Reflective journal | 92 | 3 |
| Student portfolio | 79 | 2 |
| Other | 31 | 1 |
| Total | 3,200 |
In close collaboration with Acxiom Corporation, the distance learning campus of National American University has piloted a project to further authenticate the identities of online students. The success of this project will advance the credibility of the institution’s online delivery options by adding yet another step toward identity verification of online students situated throughout the world. (Bailie & Jortberg, 2008)
Considering this approach in the context of academic necessity, it may one day validate the argument for the sale, collection, and storage of private data. By using authentication methods employed by financial institutions, NAU, in effect, eliminates student concerns for authenticating overtly with a third party (Bailie & Jortberg, 2008). To ease concerns, NAU offers the following in frequently asked questions:
How Do You Verify the Identity of Online Learners?: We pose questions that require the student to answer with information about their demographics such as where they lived in the past or what type of car they have owned. These questions are called “out of wallet” because they are from the past and the data are not usually found in an individual’s wallet. The questions are derived from public data sources and managed by a third party, independent of our institution. (Bailie & Jortbert, 2008, Appendix)
From a practical perspective, the union of academia and corporate might present an issue for some. NAU and Acxiom remained carefully within the guidelines of “Family Educational Rights and Privacy Act (FERPA), selecting directory-only data of students who have been properly identified by the university and … revealed to Acxiom so that supplemental data can be mined from the company’s databases” (Bailie & Jortberg, 2008).
Biosig-ID and ClickID
In another pilot, Houston Community College contracted with Biometric Signature ID to run a proof of technology using their dynamic signature/gesture technology to authenticate student identity remotely (BioSigID and Houston Community College,, 2011). The objective was to
test a solution that would allow more computer based exams at home while maintaining the highest integrity levels, Houston Community College contracted with Biometric Signature ID to run a proof of technology using their dynamic signature/gesture technology to authenticate student identity remotely. (p. 2)
The pilot project convinced HCC BioSig-ID and Click-ID met their concept for the ideal solution to: respect student privacy, be delivered at random, periodic points in the delivery of course content, be cost effective and offer the highest deterrent to academic dishonesty. BioSig-ID is not a biometric fingerprint authentication. Levey and Maynard (2011) describe it as follows:
BioSig-ID does not require hardware to be activated. Instead, BioSig-ID is software only and is activated using flash, a component used in all computers. BioSig-ID provides physical authentication of the user by measuring unique characteristics of the individual commonly referred as “something that you are”. The user signs or draws their password in the software using just a mouse, stylus or touchpad. The software also incorporates “something that you know” making it a true multi-factor authentication system and ideally suited for remote authentication for students. (p. 3.)
BioSig-ID may encounter little resistance when considering invasive privacy concerns. As evidenced in Figure 1, physical biometrics is not employed in this technology. A student need only create a profile utilizing a method reminiscent of handwriting analysis employing a tool, such as a mouse or stylus.
In this technology, a student will also authenticate a ClickID, which is simply a matter of clicking a series of images that are used as a second level of validation to create or recover a BioSig-ID. A detailed instructional video on the creation of a BioSig-ID can be viewed on YouTube titled BioSig-ID Signature Biometrics | ID Verification | How-To Multi-factor Authentication. The link is available in the References section of this article. Financial institutions regularly utilize these methods in combination with out-of-wallet information and security questions for a virtually, nonbiologically invasive authentication. The less attainable academic dishonesty becomes and the more diligent institutions become, the greater the value placed on academic integrity.
Transitioning From Academic to Corporate
Shifting Student Populations
Online learners are a distinct subgroup in higher education. They tend to be older and have a higher grade point average than students in traditional programs. For example, Diaz has noted that online students received twice as many As as traditional students and half as many Ds and Fs. This shift to a more mature student population suggests that more students are either already professionals or fewer will enter the workforce as traditional interns.
A Case for Ethics and Professional Integrity
Case Study
The Institute for Certification of Computing Professionals (ICCP) is a nonprofit, professional organization with an international member base. When considering the soaring rate of violations reported among undergraduates, it is critical for students to acquire a paradigm suited for entering the workforce. ICCP represents a sound example for preparation.
ICCP Background
The Institute for Certification of Computing Professionals (ICCP) is a nonprofit corporation founded in 1973. It covers a broad range of conduct for ICCP Certified Computing Professionals (CCP). Far removed from certification mills or organizations that afford a rapid review process to certification, ICCP certified professionals must meet stringent qualifications and possess a minimum of five years validated industry experience. CCPs are held to or must have:
a high standard of skill and knowledge;
a confidential relationship with people served;
public reliance upon the standards of conduct and established practice; and
the observance of an ethical code.
ICCP’s multifaceted code of ethics consists of a preamble, code of conduct, code of good practice, and a procedure for revocation of certification, should violations occur.
Kewal Dhariwal, executive director of CCP, I.S.P., comments, “ICCP offers online courses with examinations for each of the 12 modules of learning.” ICCP’s authentication employs web-cam proctoring, presentation of government issued identification for both national and international prospects, and in the future we might explore biometric authentication, if integrity becomes a problem. While ICCP shares concerns with the academic community regarding student authentication; ICCP has consistently maintained the ethical leanings it requires for its certified professionals. This may be due to Dhariwal’s stringent promotion of professionalism and ethics in parallel with certification. Additionally, a significant factor ranking ICCP high among certifying institutions is the agnostic positioning of ICCP certification. In the scope of certification, an agnostic certification is perhaps boundless, requiring larger responsibility to fulfill the intent of the certification. Agnosticism makes ICCP certification portable across many disciplines within the industry, as well.
ICCP’s student certification, the Associated Computing Professional is offered to graduating college students on the local level, at the student conferences and online. Professionalism, ethics, and integrity are all standards in the ICCP agnostic certification programs.
Authentication Technology
Advances in Authentication
Advanced technologies are increasingly being offered through partnerships between academia and the business sector. Global authentication has been considered in the interest of facilitating exchanges between research departments of institutions in foreign countries (Haeusser, 2007). Haeusser conceptualized how authentication evolved over time and transited the following stages:
1.0) Single Sign on, to
1.5) Federated IDs using open source technology named Shibboleth, to
2.0) User centric ID, where the user controls the level of privacy
Conclusion
Authentication in higher education is critical to academic integrity. New technologies are being employed in the effort to adjust the paradigm on academic dishonesty. These technologies must be nonbiological and noninvasive if they are to be efficiently diffused. It is not a question of whether we can achieve it, we must achieve it.


