Privacy-Preserving Online Proctoring via Data Fragmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online proctoring methods compromise test-taker privacy by collecting and retaining vast amounts of biometric data, which can lead to identity theft and misuse, while prioritizing cheating detection over privacy concerns.
Innovation Solution
A privacy-preserving online proctoring method that uses cryptographic keys to anonymize and scramble test-taker data, ensuring only authorized entities access encrypted fragments, allowing test-takers to control data retention and usage, thereby preventing misuse and maintaining privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If online proctoring systems collect and retain vast amounts of biometric data to detect cheating, then cheating detection capability is improved, but test-taker privacy is compromised and risk of identity theft increases
Solution Approach 1:
The patent divides the proctoring data into multiple fragmented pieces, where each fragment contains only a portion of the biometric information. No single fragment can be used to identify or surveil the test-taker, yet collectively the fragments enable cheating detection. This segmentation resolves the contradiction by making the data unusable for privacy violations while preserving its utility for detecting cheating behaviors.
Solution Approach 2:
The patent introduces cryptographic keys as an intermediary layer between the raw biometric data and the entities that need to analyze it. These keys enable authorized access for cheating detection while preventing unauthorized access that could lead to identity theft. The cryptographic intermediary transforms the data into an encrypted form that protects privacy while maintaining detectability of cheating patterns.
2Reliability
If proctoring services gather and retain personally identifiable information (PII) to monitor test-takers, then proctoring effectiveness is improved, but susceptibility to data breaches and misuse increases
Solution Approach 1:
The patent segments PII into multiple encrypted fragments distributed across different storage locations or systems. This segmentation reduces the impact of any single data breach, as attackers would need to compromise multiple fragmented pieces to reconstruct usable PII. The segmentation maintains proctoring effectiveness by preserving the ability to access and analyze test-taker information when needed for legitimate monitoring purposes.
Solution Approach 2:
The patent transforms PII from its original readable form into encrypted parameter representations that can only be decoded with specific cryptographic keys. This parameter change from plaintext to encrypted form fundamentally alters the data's state, making it useless for unauthorized access while preserving its utility for authorized proctoring operations. The encrypted parameters can still be processed for cheating detection without exposing the underlying PII.
3Productivity
If automated AI proctoring software is deployed to monitor students, then productivity and scalability are improved, but extent of surveillance and privacy intrusion increases
Solution Approach 1:
The patent segments the automated surveillance function into multiple independent analysis modules that process different aspects of test-taker behavior separately. Each module analyzes specific patterns (e.g., facial expressions, keystroke patterns, camera angles) and reports findings without accessing complete personal information. This segmentation enables high-scale automated processing while limiting the surveillance intensity any single system component can exert on individual test-takers.
Data Source
AI summary
A method and system for online proctoring of tests while preserving privacy of test-taker is disclosed. Proctoring data, which include video and audio data from at least one camera and a microphone monitoring the test-taker and the test environment, is chopped up into data fragments. Each fragment is altered to replace personally identifiable information, and the altered fragment is encrypted using a cryptographic key. The chronological order of fragments is also scrambled. Encrypted and altered data fragments are distributed to a pool of proctors who review the encrypted fragment for suspicious behavior. Suspicious fragments are further compared with original, unaltered versions of the fragments to confirm suspicious behavior, and render a verdict. The test-taker is aware of, and explicitly consents to the processing of a fragment by a proctor. A secure, custom viewer for the fragments also allows the test-taker to control the number of times a proctoring data segment can be viewed. Our method and system ensure the privacy of the proctoring data by explicitly authorizing every entity that processes a proctoring data fragment, and limiting number of views of the fragment, while allowing independent evaluation of proctoring data for different forms of cheating.


