Protecting Individualized Education and Therapy Records Via Two-Tier Integrity Verification in Distributed Educational Systems
Main Article Content
Abstract
As special education and disability support services become more digitized, the use of distributed systems for storing individualized education plans (IEPs), therapy records, behavioral assessments and assistive intervention data has grown. While frameworks currently use encryption and access control, there are threats to data integrity during the data restoration process that are less addressed, including cases of manipulation of data during reconstruction, silent corruption of the ciphertext, and fragment tampering. This corruption can affect the continuity of education as well as disability support services for persons with disabilities. In this paper, the concept of Two-Tier Integrity Verification Unit (IVU) for secure restoration of Distributed Educational Records is proposed. The framework does deterministic cryptographic integrity verification at two points before decrypting. Tier 1 uses a hash function, SHA-256, on each individual piece of ciphertext to prevent corrupt data and unauthorized changes from affecting the storage-node level. Tier 2 verifies the integrity of the reconstructed cipher text, to detect fragment reordering and reconstruction boundary attacks that fragment level verification would not detect. Only if both the verification steps are passed, will the decryption be carried out. Evaluation on a synthetic educational-support dataset showed that the overhead for total IVUs is 43.0 ms for a 10 MB dataset, while detecting tamper is effective. The proposed framework ensures integrity assurance in limited time to minimal duration of restoration, enabling secure and trustworthy management of distributed educational and therapy records of people with disabilities.


