The Identity Trust Chain: A governance framework for attribute-level identity provenance and assurance in higher education
This paper develops the Identity Trust Chain (ITC), a standards-informed governance framework for attribute-level identity provenance and assurance in higher education enrollment systems. Motivated by ghost-student and FAFSA-related fraud patterns, the paper argues that institutional identity risk is broader than authentication. The central problem is whether the attributes composing a student identity have known sources, validation histories, assurance levels, freshness conditions, and permitted uses when relied upon for institutional decisions. Using an abstracted enrollment stack composed of identity providers, customer relationship management systems, student information systems, learning management systems, financial-aid systems, payment systems, and federated services, the paper identifies where identity trust is created, transformed, propagated, degraded, and revalidated. The ITC synthesizes NIST digital identity guidance, REFEDS assurance concepts, W3C provenance modeling, federation trust practices, zero trust principles, and NIST Cybersecurity Framework 2.0 governance logic into a conceptual model for institutional decision-making. The contribution is not a new authentication technology or forensic method, but a governance framework for improving attribute trust, auditability, decision justification, and fraud resistance across higher education identity workflows.
