SlideShare a Scribd company logo
1 of 27
www.openathens.org
Authentication technology update: OpenAthens
Phil Leahy
Service Relationship Manager
phil.leahy@eduserv.org.uk
www.openathens.org
Coming up
• The access management toolkit
• Security, privacy and personalisation
• What opportunities are new technologies bringing?
• How OpenAthens helps organisations and their content
provider suppliers
www.openathens.org
Helping over 2,200 organisations
in 48 countries, enable access to
hundreds of thousands of journals,
databases and ebooks for over
4 million end users.
www.openathens.org
The access management toolkit
• Vendor-supplied credentials
• Referral URLs
• IP recognition
• Peer-to-peer SAML connections
• Federated access management
www.openathens.org
www.openathens.org
Changing user requirements
• Mobile access
is key
• Personalisation is
expected
• Multiple devices are
used
www.openathens.org
Changing librarian requirements
• More tech services to manage
• Multiple tech services must integrate
• Monitor e-library engagement
www.openathens.org
What is local authentication?
• Uses existing usernames and passwords, typically held
in Active Directory
• Same account used for ‘local’ and external systems
• VLE
• Google Apps / Office 365
• OpenAthens
• Reduces administration
• Reduces user queries
www.openathens.org
Security is paramount
• Authentication within Federations uses SAML
• Data encryption comes as standard
• Individual level accountability
• Permission setting features – easier to comply with
restricted content licences
• Authentication servers monitored for misuse
www.openathens.org
Directory integrations
CAS (Client Access Server)
www.openathens.org
Build against an API
• Log your users into the system based on credentials
stored in any system you can gain programmatic access
to
• Great when you cannot use other connection types
www.openathens.org
Connecting to SAML applications
• OpenAthens can interact with many Apps
• Better overall experience for end users
• ‘True’ single sign-on
www.openathens.org
Integration with SAML applications
www.openathens.org
Is user privacy at risk?
• SAML encrypts data by default…
• …but is that sufficient?
• personalisation requires that content providers know
something about a user…
• …what is acceptable?
3l3dfaspfr96k36vcsj6bjl6r8
https://twitter.com/lisalibrarian/status/927534622799548416
www.openathens.org
Attribute release in OpenAthens
www.openathens.org
• Benefit from SAML without installing it
• OpenAthens Cloud offers the same benefits
• OpenID Connect is the hook…
• …but what is OpenID Connect?
OpenAthens Cloud
www.openathens.org
Federation standards
OpenID Connect
• Web-scale
• Modern, developer-
friendly
• Only implicit trust
SAML
• Enterprise
• Mid-2000s tech, hard to
adopt
• Scalable trust-network
www.openathens.org
OpenAthens Cloud
www.openathens.org
www.openathens.org
OpenAthens Wayfinder:
helping content providers help users
www.openathens.org
New technologies = new opportunities?
www.openathens.org
Google Scholar CASA
“CASA builds on Google Scholar’s Subscriber Links program which
provides direct links in the search interface to subscribed collections for on-
campus users. With CASA, a researcher can start a literature survey on
campus and resume where she left off once she is home, or travelling, with
no hoops to jump through. Her subscribed collections are highlighted in
Google Scholar searches and she is able to access articles in exactly the
same way as on campus.”
Users must access on-campus at least every 30 days to maintain off-
campus access.
https://home.heinonline.org/blog/2017/09/casa-en-nuestra-casa-casa-in-our-house/
www.openathens.org
BeyondCorp at Google
• Principles
• Connecting from a particular network must not determine
which services you can access.
• Access to services is granted based on what we know about
you and your device.
• All access to services must be authenticated, authorized and
encrypted.
https://cloud.google.com/beyondcorp/
www.openathens.org
Federation standards
OpenID Connect
• Web-scale
• Modern, developer-
friendly
• Only implicit trust
SAML
• Enterprise
• Mid-2000s tech, hard to
adopt
• Scalable trust-network
Convergence?
www.openathens.org
More information
What does it take to run an access management
federation?
http://bit.ly/2AWSUUz
OpenAthens Cloud uses OpenID Connect
http://bit.ly/2y3pZz6
www.openathens.org
Phil Leahy
OpenAthens Service Relationship Manager
phil.leahy@eduserv.org.uk
+44 (0)1225 474302
Any questions?
What does it take to run an access management
federation?
http://bit.ly/2AWSUUz
OpenAthens Cloud uses OpenID Connect
http://bit.ly/2y3pZz6
Contacts
Josh Howlett, Head of trust and identity, Jisc
Josh.Howlett@jisc.ac.uk
Phil Leahy, OpenAthens Service Relationship Manager
phil.leahy@eduserv.org.uk
Tasha Mellins-Cohen, Director of Publishing, Microbiology Society
t.mellins-cohen@microbiologysociety.org
Feel free to e-mail your questions and look out for the slides on
uksg.org/webinars/authentication

More Related Content

What's hot

Inter Lab 2006 Open Process Web Design Through W I K I
Inter Lab 2006    Open Process Web Design Through  W I K IInter Lab 2006    Open Process Web Design Through  W I K I
Inter Lab 2006 Open Process Web Design Through W I K I
guestd43c7f
 
Digital Doha Summit - ICT Qatar and Open Source
Digital Doha Summit - ICT Qatar and Open SourceDigital Doha Summit - ICT Qatar and Open Source
Digital Doha Summit - ICT Qatar and Open Source
Forum One
 
Open public 1.0 drupal Government Days
Open public 1.0   drupal Government DaysOpen public 1.0   drupal Government Days
Open public 1.0 drupal Government Days
Phase2
 

What's hot (16)

Inter Lab 2006 Open Process Web Design Through W I K I
Inter Lab 2006    Open Process Web Design Through  W I K IInter Lab 2006    Open Process Web Design Through  W I K I
Inter Lab 2006 Open Process Web Design Through W I K I
 
Suguk Southampton CodePlex - March 2014
Suguk Southampton   CodePlex - March 2014Suguk Southampton   CodePlex - March 2014
Suguk Southampton CodePlex - March 2014
 
SIS integration with Moodle using Learning Information Services (LIS)
SIS integration with Moodle using Learning Information Services (LIS)SIS integration with Moodle using Learning Information Services (LIS)
SIS integration with Moodle using Learning Information Services (LIS)
 
Integrating SAIP with Moodle using LIS - HEUG EMEA 2013
Integrating SAIP with Moodle using LIS - HEUG EMEA 2013Integrating SAIP with Moodle using LIS - HEUG EMEA 2013
Integrating SAIP with Moodle using LIS - HEUG EMEA 2013
 
Tips for Driving Learning Success with Moodle LMS Reporting
Tips for Driving Learning Success with Moodle LMS ReportingTips for Driving Learning Success with Moodle LMS Reporting
Tips for Driving Learning Success with Moodle LMS Reporting
 
Digital Doha Summit - ICT Qatar and Open Source
Digital Doha Summit - ICT Qatar and Open SourceDigital Doha Summit - ICT Qatar and Open Source
Digital Doha Summit - ICT Qatar and Open Source
 
Looking tofuture
Looking tofutureLooking tofuture
Looking tofuture
 
Ministry in a digital age
Ministry in a digital ageMinistry in a digital age
Ministry in a digital age
 
SharePoint Migration Series: Success Takes Three Actions
SharePoint Migration Series: Success Takes Three ActionsSharePoint Migration Series: Success Takes Three Actions
SharePoint Migration Series: Success Takes Three Actions
 
Open public 1.0 drupal Government Days
Open public 1.0   drupal Government DaysOpen public 1.0   drupal Government Days
Open public 1.0 drupal Government Days
 
BrightGen's Summer 16 Release Webinar
BrightGen's Summer 16 Release WebinarBrightGen's Summer 16 Release Webinar
BrightGen's Summer 16 Release Webinar
 
Tips and Tricks to Optimize your Digital Resources
Tips and Tricks to Optimize your Digital ResourcesTips and Tricks to Optimize your Digital Resources
Tips and Tricks to Optimize your Digital Resources
 
Hybrid Dilemma: Dividing Content Between Azure, Office 365 & SharePoint 2016
Hybrid Dilemma: Dividing Content Between Azure, Office 365 & SharePoint 2016Hybrid Dilemma: Dividing Content Between Azure, Office 365 & SharePoint 2016
Hybrid Dilemma: Dividing Content Between Azure, Office 365 & SharePoint 2016
 
USG Summit - September 2014 - Web Management using Drupal
USG Summit - September 2014 - Web Management using DrupalUSG Summit - September 2014 - Web Management using Drupal
USG Summit - September 2014 - Web Management using Drupal
 
Enterprise Level Tools and solutions for Accessibility - WorldSpace, Amaze an...
Enterprise Level Tools and solutions for Accessibility - WorldSpace, Amaze an...Enterprise Level Tools and solutions for Accessibility - WorldSpace, Amaze an...
Enterprise Level Tools and solutions for Accessibility - WorldSpace, Amaze an...
 
Data harmony update 2021
Data harmony update 2021 Data harmony update 2021
Data harmony update 2021
 

Similar to UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh Howlett, Jisc and Phil Leahy, Eduserv

Similar to UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh Howlett, Jisc and Phil Leahy, Eduserv (20)

Quick wins for an easier user journey
Quick wins for an easier user journeyQuick wins for an easier user journey
Quick wins for an easier user journey
 
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
 
OpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital content
 
Today's forecast for your campus: BLUEcloud
 Today's forecast for your campus: BLUEcloud Today's forecast for your campus: BLUEcloud
Today's forecast for your campus: BLUEcloud
 
Remote xs
Remote xsRemote xs
Remote xs
 
Open Source & Libraries
Open Source & LibrariesOpen Source & Libraries
Open Source & Libraries
 
Open source systems
Open source systemsOpen source systems
Open source systems
 
Help your users to discover your content with OpenAthens and Link Resolvers
Help your users to discover your content with OpenAthens and Link ResolversHelp your users to discover your content with OpenAthens and Link Resolvers
Help your users to discover your content with OpenAthens and Link Resolvers
 
OER Authoring and Delivery Platforms
OER Authoring and Delivery PlatformsOER Authoring and Delivery Platforms
OER Authoring and Delivery Platforms
 
Online Journal Management using Open Journal Systems (OJS)
Online Journal Management using Open Journal Systems (OJS)Online Journal Management using Open Journal Systems (OJS)
Online Journal Management using Open Journal Systems (OJS)
 
ufsojs-161024084446 (1).pdf
ufsojs-161024084446 (1).pdfufsojs-161024084446 (1).pdf
ufsojs-161024084446 (1).pdf
 
Geek out : Adding Coding Skills to Your Professional Repertoire
Geek out: Adding Coding Skills to Your Professional RepertoireGeek out: Adding Coding Skills to Your Professional Repertoire
Geek out : Adding Coding Skills to Your Professional Repertoire
 
Open Access Tools
Open Access ToolsOpen Access Tools
Open Access Tools
 
Use of "NewGenLib" Open Source Software for Library Automation, Digital Libra...
Use of "NewGenLib" Open Source Software for Library Automation, Digital Libra...Use of "NewGenLib" Open Source Software for Library Automation, Digital Libra...
Use of "NewGenLib" Open Source Software for Library Automation, Digital Libra...
 
Library portal by Gaurav Boudh
Library portal by Gaurav BoudhLibrary portal by Gaurav Boudh
Library portal by Gaurav Boudh
 
Brou
BrouBrou
Brou
 
Sreedevi.v.s
Sreedevi.v.sSreedevi.v.s
Sreedevi.v.s
 
Resource discovery tools
Resource discovery toolsResource discovery tools
Resource discovery tools
 
Social networks: technical issues
Social networks: technical issuesSocial networks: technical issues
Social networks: technical issues
 

More from UKSG: connecting the knowledge community

UKSG 2024 - Open infrastructure and standards: small bodies, big impact
UKSG 2024 - Open infrastructure and standards: small bodies, big impactUKSG 2024 - Open infrastructure and standards: small bodies, big impact
UKSG 2024 - Open infrastructure and standards: small bodies, big impact
UKSG: connecting the knowledge community
 

More from UKSG: connecting the knowledge community (20)

UKSG 2024 Plenary Session 3 - There is No List: (How) Can We Combat “Predator...
UKSG 2024 Plenary Session 3 - There is No List: (How) Can We Combat “Predator...UKSG 2024 Plenary Session 3 - There is No List: (How) Can We Combat “Predator...
UKSG 2024 Plenary Session 3 - There is No List: (How) Can We Combat “Predator...
 
UKSG 2024 From algorithms to empowerment by Christina Dinh Nguyen.pdf
UKSG 2024 From algorithms to empowerment by Christina Dinh Nguyen.pdfUKSG 2024 From algorithms to empowerment by Christina Dinh Nguyen.pdf
UKSG 2024 From algorithms to empowerment by Christina Dinh Nguyen.pdf
 
UKSG 2024 Plenary 4 - Combining Open Access research and large language model...
UKSG 2024 Plenary 4 - Combining Open Access research and large language model...UKSG 2024 Plenary 4 - Combining Open Access research and large language model...
UKSG 2024 Plenary 4 - Combining Open Access research and large language model...
 
UKSG 2024 Plenary 3 - There is No List: (How) Can We Combat “Predatory” Publi...
UKSG 2024 Plenary 3 - There is No List: (How) Can We Combat “Predatory” Publi...UKSG 2024 Plenary 3 - There is No List: (How) Can We Combat “Predatory” Publi...
UKSG 2024 Plenary 3 - There is No List: (How) Can We Combat “Predatory” Publi...
 
UKSG 2024 Plenary 2 - Let's Talk About Green
UKSG 2024 Plenary 2 - Let's Talk About GreenUKSG 2024 Plenary 2 - Let's Talk About Green
UKSG 2024 Plenary 2 - Let's Talk About Green
 
UKSG 2024 Plenary 2 - Are we there yet? A review of transitional agreements i...
UKSG 2024 Plenary 2 - Are we there yet? A review of transitional agreements i...UKSG 2024 Plenary 2 - Are we there yet? A review of transitional agreements i...
UKSG 2024 Plenary 2 - Are we there yet? A review of transitional agreements i...
 
UKSG 2024 Plenary 2 - What did we Read, What did we Publish: Distilling the d...
UKSG 2024 Plenary 2 - What did we Read, What did we Publish: Distilling the d...UKSG 2024 Plenary 2 - What did we Read, What did we Publish: Distilling the d...
UKSG 2024 Plenary 2 - What did we Read, What did we Publish: Distilling the d...
 
UKSG 2024 Lightning 2 - How GetFTR Supports Discovery and Access of OA Content
UKSG 2024 Lightning 2 - How GetFTR Supports Discovery and Access of OA ContentUKSG 2024 Lightning 2 - How GetFTR Supports Discovery and Access of OA Content
UKSG 2024 Lightning 2 - How GetFTR Supports Discovery and Access of OA Content
 
UKSG 2024 Lightning 2 - Advocating for data sharing: messaging frameworks for...
UKSG 2024 Lightning 2 - Advocating for data sharing: messaging frameworks for...UKSG 2024 Lightning 2 - Advocating for data sharing: messaging frameworks for...
UKSG 2024 Lightning 2 - Advocating for data sharing: messaging frameworks for...
 
UKSG 2024 Lightning 2 - All Watched Over By Machines That Love Open Research
UKSG 2024 Lightning 2 - All Watched Over By Machines That Love Open ResearchUKSG 2024 Lightning 2 - All Watched Over By Machines That Love Open Research
UKSG 2024 Lightning 2 - All Watched Over By Machines That Love Open Research
 
UKSG 2024 Lightning 1 - Responding to the UN SDG Publishers Compact – Bristol...
UKSG 2024 Lightning 1 - Responding to the UN SDG Publishers Compact – Bristol...UKSG 2024 Lightning 1 - Responding to the UN SDG Publishers Compact – Bristol...
UKSG 2024 Lightning 1 - Responding to the UN SDG Publishers Compact – Bristol...
 
UKSG 2024 Lightning 1 - Practical steps towards an open research culture: Bui...
UKSG 2024 Lightning 1 - Practical steps towards an open research culture: Bui...UKSG 2024 Lightning 1 - Practical steps towards an open research culture: Bui...
UKSG 2024 Lightning 1 - Practical steps towards an open research culture: Bui...
 
UKSG 2024 - Open infrastructure and standards: small bodies, big impact
UKSG 2024 - Open infrastructure and standards: small bodies, big impactUKSG 2024 - Open infrastructure and standards: small bodies, big impact
UKSG 2024 - Open infrastructure and standards: small bodies, big impact
 
UKSG 2024 - Reckoning or Retreat? A Longitudinal Look at DEIA in Scholarly Co...
UKSG 2024 - Reckoning or Retreat? A Longitudinal Look at DEIA in Scholarly Co...UKSG 2024 - Reckoning or Retreat? A Longitudinal Look at DEIA in Scholarly Co...
UKSG 2024 - Reckoning or Retreat? A Longitudinal Look at DEIA in Scholarly Co...
 
UKSG 2024 - You don't know what you've got till it's gone: Future directions ...
UKSG 2024 - You don't know what you've got till it's gone: Future directions ...UKSG 2024 - You don't know what you've got till it's gone: Future directions ...
UKSG 2024 - You don't know what you've got till it's gone: Future directions ...
 
UKSG 2024 - Vision, mission, passion: how UK University Presses collaborate t...
UKSG 2024 - Vision, mission, passion: how UK University Presses collaborate t...UKSG 2024 - Vision, mission, passion: how UK University Presses collaborate t...
UKSG 2024 - Vision, mission, passion: how UK University Presses collaborate t...
 
UKSG - 2024 - Fostering an Open Research culture: ARU's Graduate Trainee Seco...
UKSG - 2024 - Fostering an Open Research culture: ARU's Graduate Trainee Seco...UKSG - 2024 - Fostering an Open Research culture: ARU's Graduate Trainee Seco...
UKSG - 2024 - Fostering an Open Research culture: ARU's Graduate Trainee Seco...
 
UKSG 2024 - Creating credibility through community: Encouraging high quality ...
UKSG 2024 - Creating credibility through community: Encouraging high quality ...UKSG 2024 - Creating credibility through community: Encouraging high quality ...
UKSG 2024 - Creating credibility through community: Encouraging high quality ...
 
UKSG 2024 - Author Identity Metadata: Why a Small Publisher Can Address a Maj...
UKSG 2024 - Author Identity Metadata: Why a Small Publisher Can Address a Maj...UKSG 2024 - Author Identity Metadata: Why a Small Publisher Can Address a Maj...
UKSG 2024 - Author Identity Metadata: Why a Small Publisher Can Address a Maj...
 
UKSG 2024 - Captivate, Connect, and Convert: Unlocking the art of Collections...
UKSG 2024 - Captivate, Connect, and Convert: Unlocking the art of Collections...UKSG 2024 - Captivate, Connect, and Convert: Unlocking the art of Collections...
UKSG 2024 - Captivate, Connect, and Convert: Unlocking the art of Collections...
 

Recently uploaded

Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Krashi Coaching
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
fonyou31
 

Recently uploaded (20)

BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Student login on Anyboli platform.helpin
Student login on Anyboli platform.helpinStudent login on Anyboli platform.helpin
Student login on Anyboli platform.helpin
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Disha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdfDisha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdf
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SD
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
9548086042 for call girls in Indira Nagar with room service
9548086042  for call girls in Indira Nagar  with room service9548086042  for call girls in Indira Nagar  with room service
9548086042 for call girls in Indira Nagar with room service
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communication
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 

UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh Howlett, Jisc and Phil Leahy, Eduserv

Editor's Notes

  1. This is the impact of OpenAthens single sign-on software – across the globe. Publishers can add their content to a user’s existing portfolio instead of existing within its own silo. We’ve got ten years experience of developing Shibboleth and SAML software which is used by some of the world’s largest content providers including Wolters Kluwer Health, New Scientist and the FT. The OpenAthens Federation is the trust authority which allows content providers and their customers to connect to each other without requiring technical setup each time.
  2. Here is a list of the access management tools typically used by organisations subscribing to external content. It’s been pointed out to me that the shortfalls of current authentication technologies were well covered at the UKSG conference earlier this year, but there have already been several questions submitted along those lines so I’m going to try and find the sweet spot between that and current technologies and future opportunities which are more interesting. Easily shared and relies on security through obscurity Easily shared and relies on security through obscurity How long have you got? (“Developments in proxy servers”, “Comparison between OA and Library Proxy”, “How it works and cost comparisons with EZProxy etc”, “Comparison with EZproxy”) Identifies only the organisation Cannot identify offenders who breach license terms No meaningful statistics Have to maintain a list of IP addresses with every supplier Remote access requires VPN or additional proxy Personalisation either non-existent or requires separate registration Expensive to implement and manage, inefficient single-use peer-to-peer connections
  3. This is a typical federated user journey that our software helps deliver. So – we have an end user browsing the web looking for academic or scholarly content And all the time they are hitting barriers and being asked for a username and password They get frustrated But – in comes OpenAthens! With just one username and password, the patron can access an array of online resources – and crucially move between resources on different publisher sites
  4. Patrons become more mobile – fewer ties to the physical library building, study is anywhere and everywhere Personalization is expected – we’re all used to the Amazon or Netflix experience and at least in the UK, there is an expectation that library resources should behave in the same manner – saved searches, recommended favourites etc. Multiple devices are used for study – access to library content needs to be consistent and seamless regardless of the device used
  5. And for librarians… More tech services to manage – VLE, Discovery, Website, Proxy Server Multiple tech services must integrate – single sign-on is key Monitor and report on E-library engagement – who’s accessing our services, how often and from where?
  6. Here’s a typical scenario: when a new user enrols at a university or starts work at a new job, that organisation will have a process which automatically grants access to the internal and external resources they need to participate in their course or do their job. That process applies the appropriate permissions and controls to ensure they can only access what they entitled to and will typically include access to their nearest printer, the network drives for access to the documents they need, a VLE, discovery tools and/or LMS and increasingly, their organisation’s subscription content – all with a single username and password. Most popular choice across all markets. OpenAthens is part of an ecosystem and our docs help organisations integrate different components
  7. Multi-country misuse Audit logs now available in OpenAthens (“How can the usage (not just login) statistics be captured?”)
  8. The options available to subscribing organisations on how to participate in an access management federation are better than ever. “The ability to restrict access to sub-groups within the University” “How is the access by temporary guests handled by OpenAthens?” “Configuring access for overseas/partnership institutions” “Authentication for partnerships - based in the UK and abroad” OpenAthens offers these connection options so whatever your organisation has in place, it’s likely that OpenAthens can help an organisation use Shibboleth or SAML because…
  9. …we also offer tools which allow self-built interfaces. Offers maximum flexibility – but it requires developer effort at the organisation. “What would be the best means of authentication to use for a small institution with limited resources to access eBooks?”
  10. So the fact that… It is the nature of federated access management in general and OpenAthens products in particular to use a standards based approaches wherever possible. This allows true SSO with a number of apps such as…
  11. This shows a number of common apps our customer use OpenAthens to integrate with. OpenAthens plays well with all discovery services “We are moving to Alma Summer of 2018 I wonder which authentication to use, EZ Proxy or Open Athens for the link resolver”
  12. But how can all that happen in a privacy-protecting way? Earlier on I said personalisation is now expected from a range of services such as Amazon or Netflix. There is a view that: without personalisation, none of the benefits of a modern digital service are available, i.e. more engagement, attracting users to return, learning more about their needs and tailoring products accordingly. That level of detail helps everyone. It helps content providers segment their products and direct it at particular users, and by providing greater transparency of how collections are being used, it helps an organisation make more informed purchase decisions. But… “a (happily very vocal) majority who are unwilling to compromise user privacy for the sake of some assessment metrics” Do users now expect that from library services too? Some librarians are concerned about the privacy issues this raises, and they see IP recognition as the better option precisely because it’s anonymous. Take a look at this image sent to me during a dialogue I had over Twitter with a US librarian (although this view is not exclusive to the US). This is a detailed user consent page which explains which attributes about this user were going to be passed to the content provider. [description] If the user did not provide their consent, they were not permitted to see the content.
  13. Would there be more confidence around privacy if IdPs took a closer look at their attribute release policies, and content providers were more circumspect about the attributes they requested? Many users will submit this same level of personal information on a form they’re presented with the first time they access a service. Is that substantially different from a Netflix or Amazon subscription? However, if a content provider receives a narrower set of attributes which has no identifying information but which allows the user to personalise the experience, e.g. via saved searches and alerts, would that be sufficient to satisfy the content provider? This is the functionality OpenAthens makes available to organisations so they can control attribute release quickly and easily. And we’re making similar products available to content providers so they can leverage the benefits of Shibboleth and SAML without having to become experts in that technology, so here’s a brief word about that.
  14. But there is an alternative. It is now possible to derive all the benefits which SAML brings without having to deploy it. As I said earlier, OpenAthens has ten years’ experience of developing SAML software and having seen the issues which I just described for some time, we decided to take a new approach and developed OpenAthens Cloud. The only technology a content provider needs to deploy is OpenID Connect – everything else is managed in our web dashboard. OpenID Connect is supported by key industry players like Symantec and Microsoft. It's a newer technology than SAML but unlike SAML, it's extensible to web-based native apps as well as mobile applications.
  15. SAML is Enterprise – connections between identities and services within a scope Old tech XML, SOAP – mid 2000s Supports ’trusted relationships’ Formation of communities OIDC is Multi-billion user services JWT/ REST, Developer friendly Mobile- native Self-asserted trust
  16. I’m sure many of you will be familiar with seeing Google login options on a number of web services – that process uses OpenID Connect and as you can see, one of the benefits is a consistent login experience.
  17. And anytime you see a PayPal payment option on a website, it is using OpenID Connect to let you login via PayPal. Let me be clear: OpenAthens Cloud alone won't let a content provider add Google and PayPal login options to their products. But if that is on their wishlist, with OpenID Connect as the foundation that task would be easier.
  18. Here’s something else we’ve recently released for content providers, but it’s not something they can buy – any publisher registered in any Shibboleth or SAML access management federation can use it. Wayfinder is the OpenAthens Discovery Service which any publisher can deploy: Uses SAML attributes for scalability Uses domain hints and geolocation – UKFed are already promoting increased adoption of domain hints
  19. CASA = Context-Aware Scalable Authentication. Some big players are participating including HighWire – but based on Google Scholar usage.
  20. BeyondCorp had the stated goal that no Google employee should need to use a VPN. “We infer device trust based on a number of signals, some observed (last security scan, patch level, installed software, etc.) and some prescribed (assigned owner, VLAN, etc.). To handle this complexity, our inventory teams follow an automated provisioning process to ensure that new hire devices are correctly trusted at first login.” Contextual authentication is increasingly being talked about ------------------------- Contextual authentication takes into account the context of a service and deploys appropriate authentication challenge Encompasses multi-factor methods, where appropriate Intelligent IAM systems can change context dynamically (eg. location or suspicious activity) Authentication factors ---------------------- Trusted device Location/network (IP) Username/password SMS, push notification, OTP app, YubiKey Previous activity Reduce friction of authentication --------------------------------- Objective of contextual authentication is to reduce friction Misunderstanding of multi-factor is that is makes authentication more complex – inappropriate deployment No user-interaction unless necessary
  21. SAML is Enterprise – connections between identities and services within a scope Old tech XML, SOAP – mid 2000s Supports ’trusted relationships’ Formation of communities OIDC is Multi-billion user services JWT/ REST, Developer friendly Mobile- native Self-asserted trust Bottom line: with 10-12 years of investment in Shibboleth and SAML by content providers and subscribing organizations around the world, it’s not going anywhere soon. - My impression is that this is still pretty early days. There is a draft specification but it seems to be fairly early to me. There were two camps, one wanted existing OpenID implementations to work pretty much unmodified with the new spec. Others saw the need for more complexity in implementations (though there was recognition that this was a problem). I suspect some compromise will be reached.   - There is definitely a desire to learn from 10 years of SAML federations and make notable improvements, like not shipping around massive blobs of XML. Hopefully the standard will be much simpler and inline with modern APIs.