USI (Unique Student Identifier)

This page contains instructions on how to enable the Paradigm integration with the USI verification service.

Overview

The USI (Unique Student Identifier) can be verified within Paradigm if the appropriate credentials have been provided to Silverband to gain access to the USI Service. The USI verification service is separate and independent of the PRODA service. Separate credentials are required for each service.

USI Update Web Service Version 5: Read the newsletter released last 25/05/2023 here.

Please read through the Mandatory Tasks, Key Terms and Concepts, and Implications before proceeding to the Workflow.

Mandatory Tasks

  • The person obtaining an M2M key must have a personal myGov Portal account and myGovID

  • This personal myGovID must be authorised for use on behalf of the RTO company by the principal user of the company

  • The person creating the machine credential must be identified as the Machine Credential Administrator within the Relationship Authorisation Manager (RAM) system

Explanation

A machine-to-machine (M2M) credential is required for Paradigm to verify Unique Student Identifiers (USI) numbers on behalf of an organisation. Paradigm does not have permission to create a USI for any student.

The M2M credential replaces previous USI-related authentication mechanisms such as AUSKey. Be aware that the terminology surrounding the process for obtaining an M2M credential has also changed.

The person creating the M2M key will be identified as the Machine Credential Administrator signifying they have been assigned the rights to issue credentials on behalf of the RTO company inside the Relationship Authorisation Manager (RAM) government website.

Key Terms and Concepts

TermMeaning

Australian Tax Office (ATO)

Statutory agency and the principal revenue collection body for the Australian government with the responsibility for administering the Australian federal taxation system, superannuation legislation, and other associated matters.

Credential name

The name of your Paradigm site, for example demo6.edu.net.au

Entity name

The name of your institution, for example: Silverband Pty. Ltd.

Machine Credential

Machine credentials allow businesses and tax professionals to securely interact with Australian Tax Office online services through appropriately configured software systems.

Machine Credential Administrator

The individual with the authority to create a machine credential on a device to interact directly with ATO online services.

Machine to Machine (M2M)

The new authentication solution is in effect since April 2020 and replaces the previous Device AUSKey credential. The new solution has three components:

  • A machine credential – conceptually equivalent to a Device AUSkey credential

  • A Machine Authentication Service (MAS) – service provided by the ATO to validate machine credentials, and intended as a replacement to the VANguard Secure Token Service (STS) service

  • RAM – an authorisation solution which allows users to manage who can act on behalf of their business. Access Manager is accessible from RAM.

myGovID

Unique identifier for use within the MyGov Portal

MyGov Portal

The myGov portal is a secure way to access government online services. Its aim is to provide Australians with a single online destination for accessing government services with one login and one password.

Relationship Authorisation Manager (RAM)

Relationship Authorisation Manager (RAM) allows you to set up and manage relationships and authorisations across government online services. This means that RAM lets you manage who can act on behalf of your business online. RAM is managed under the purview of the Australian Tax Office.

Unique Student Identifier (USI)

Unique Student Identifier - The USI is a reference number of ten digits and letters that stays with the student for life. The USI will give the student access to an online record of your nationally recognised training in the form of a USI Transcript.

Implication(s)

A valid set of machine credentials must be provided to Silverband to enable Paradigm to be able to use USI verification functionality

Workflow

1. USI - System Access Request

There are three further sets of tasks that need to be completed to successfully obtain an M2M key for USI generation.

2. Obtain a MyGov Account

  1. The ATO is responsible for allocating each myGovID

  1. If you have not already been designated as the principal user for your organisation then you will need to identify that person and ask them to authorise you to issue machine credentials for your organisation.

4. Obtain an M2M Key

  1. To obtain/issue Machine Credential follow the instructions for steps 1 through 9 as described here: https://info.authorisationmanager.gov.au/guide-how-to-install-a-machine-credential

  2. Once you have selected the appropriate company Entity Name within RAM (Step 4) you should be able to issue a machine credential using your preferred Credential Name and enter a new Keystore password.

    1. Entity name: the name of your institution (example: Silverband Pty Ltd )

    2. Credential name: your Paradigm site name (example: demo6.edu.net.au )

  3. Record in a secure place the Keystore password that you used.

  4. Record in a secure place the Keystore file that was generated.

  5. You must provide both of these items of information to Silverband. We recommend for security reasons, that the Keystore file and the password not be provided together via the same medium, for example:

    1. The file Keystore should be added as an attachment via a support request ticket in our online helpdesk.

    2. The password should be communicated verbally via a phone call with a member of our support team so that both pieces of the authentication are provided to us separately.

Note for Windows Users

The default Windows download path for the keystore file will likely be C:\Users\<username>\AppData\Roaming\username but you may change that path at the time of download.

Last updated