Revolutionizing Consortium Access with Athens Single Sign-on A case study… Shannon Sweeny  Robin Sewell
Arizona
AZHIN Membership 4 Universities 6 Muliti-site hospitals 7 Regional Health Centers 4 State/County Health Institutions 4 VA/...
Arizona Health Information Network <ul><li>Pre-Athens Access Methods </li></ul><ul><li>Local IP-based authentication if po...
Arizona Health Information Network <ul><li>Access Requirements </li></ul><ul><ul><li>Access to ALL resources </li></ul></u...
Arizona Health Information Network <ul><li>Alternatives </li></ul><ul><ul><li>Custom-built, locally implemented solutions....
Athens At the simplest level, Classic Athens is a managed directory of usernames with librarian focussed tools to manage t...
Athens Athens Features Administrator management of user accounts Separate admin accounts for each AZHIN member organizatio...
Athens Other benefits   Single sign-on Library 2.0. Access to state-purchased resources and local institution-purchased re...
Athens <ul><li>How it works   </li></ul><ul><li>1) User logs into Athens </li></ul><ul><ul><li>Cookie is set with values i...
Athens How it works   Log into Athens User’s Info Reads cookie Verifies Info Confirms credentials Access Granted User view...
AZHIN & Athens <ul><li>What happened? </li></ul><ul><ul><ul><li>Paul Bracke and Cheaney Seth </li></ul></ul></ul><ul><ul><...
AZHIN & Athens How it was implemented Standard Athens Access MyAthens login and resource access Resources displayed by ven...
AZHIN & Athens How it was implemented AZHIN Customized Access Customizable AZHIN portal pages AZHIN member organizations c...
 
AZHIN & Athens
AZHIN & Athens Complications 1) Vendor URL variations NEJM IP access URL http://content.nejm.org NEJM Athens access URL ht...
AZHIN & Athens Achievements Access to ALL resources Access to AZHIN Resources and individual organizational subscriptions ...
AZHIN & Athens AZHIN Home page AZHIN Self registration page MyAthens login Athens Home page ssweeny @ ebsco .com
Upcoming SlideShare
Loading in …5
×

Revolutionizing consortium access with Athens single sign-on (Shannon Sweeney & Robin Sewell)

1,712 views

Published on

Robin R. Sewell
Arizona Health Sciences Library, University of Arizona
Shannon Sweeny
EBSCO Australia

Objectives and Methods

Objective

The Arizona Health Information Network (AZHIN) is a consortium of 34 member health services institutions which range in size from academic institutions to small medical clinics. The goal of this project was to improve access to resources on-site and off-site by using a single sign-on product and improve the security of the resources by implementing a password management system.

Methods

In the past non-IP authenticated on-site and off-site access required AZHIN members to use a different username and password for each vendor’s products. Athens was selected for its ability to interact with vendors, provide single sign-on access to resources, and for its password and account management features. Resource access management through Athens permissions sets simplified any changes to the resources available and provided a way for organizations to use Athens authentication for resources they purchase separately. This implementation had several challenges related to the custom delivery of resources accessed through dynamically generated web pages and the use of a custom login method. Another challenge was the management of variations in URLs used by vendors for IP and Athens authentication, especially in the context of LinkSource, EBSCO’s link resolver.

Results and Conclusions

Athens is currently in use by 27 AZHIN member organizations, having added over 2,000 users in one year. The existing vendor-based password system will be discontinued at the end of June. Three of the larger academic institutions use local proxy systems for authentication and are not using Athens. Many of the obstacles could have been over come by requiring all users to log into Athens regardless of there ability to IP authenticate. We chose to take the more difficult route in order to provide more seamless access to resources when ever possible.

Published in: Business, Technology
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total views
1,712
On SlideShare
0
From Embeds
0
Number of Embeds
23
Actions
Shares
0
Downloads
15
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide
  • Good morning all. Thank you for inviting me to talk to you today on the use of the authentication service, Athens, at the Arizona Health Information Network. I will start by familiarising you with AZHIN, the acronym used to stand for the long-ish name, and their particular needs. I will then let you know what Athens is and how that service appeared to fit those needs. I will also describe the process that was involved in implementing this service. Lastly I will show the outcome of the project and what benefits and problems were identified. A bit about me. As Electronic Resources Manager at EBSCO Australia, I have often come up against authentication and licensing problems such as: Off-site access not being able to be implemented due to lack of IT support. Network username and password access being continued to be used to access numerous resources long after the employee had left an organisation. Libraries having to pay for multi-site licenses when only one site is using a particular resource because of an inability to narrow IP access to one site. Libraries having to hand out username and password sheets, or post them on intranets in contravention of license agreements. … and many more. After a suggestion from a NSW health librarian, I researched Athens and found it had potential to solve these problems. EBSCO Australia is now the exclusive distributor in Australia and New Zealand and has had 4 sales of the product so far, with many currently trialling the service. It’s been an interesting and exciting journey to see so many librarians see their once-insurmountable problems disappear before their eyes.
  • Revolutionizing consortium access with Athens single sign-on (Shannon Sweeney & Robin Sewell)

    1. 1. Revolutionizing Consortium Access with Athens Single Sign-on A case study… Shannon Sweeny Robin Sewell
    2. 2. Arizona
    3. 3. AZHIN Membership 4 Universities 6 Muliti-site hospitals 7 Regional Health Centers 4 State/County Health Institutions 4 VA/Military hospitals 7 Small Telemedicine Clinics 1 National Association Arizona Health Information Network
    4. 4. Arizona Health Information Network <ul><li>Pre-Athens Access Methods </li></ul><ul><li>Local IP-based authentication if possible </li></ul><ul><ul><li>Problem </li></ul></ul><ul><ul><li>Non-authorised access of AZHIN resources unavoidable </li></ul></ul><ul><li>Password system for off-site access and non-IP organizations </li></ul><ul><ul><li>Problems </li></ul></ul><ul><ul><li>Difficult for users to remember passwords </li></ul></ul><ul><ul><li>Password management difficult </li></ul></ul><ul><ul><li>Shared passwords </li></ul></ul><ul><ul><li>Difficultly expiring passwords </li></ul></ul><ul><ul><li>System often document-based rather than database driven </li></ul></ul>
    5. 5. Arizona Health Information Network <ul><li>Access Requirements </li></ul><ul><ul><li>Access to ALL resources </li></ul></ul><ul><ul><li>AZHIN Resources and individual organizational subscriptions </li></ul></ul><ul><ul><li>Single off-site password access to all resources </li></ul></ul><ul><ul><li>Password access that allows user customization of passwords </li></ul></ul><ul><ul><li>Method of managing and expiring user accounts </li></ul></ul><ul><ul><li>Statistical tools to monitor use </li></ul></ul>
    6. 6. Arizona Health Information Network <ul><li>Alternatives </li></ul><ul><ul><li>Custom-built, locally implemented solutions. </li></ul></ul><ul><ul><li>Shibboleth </li></ul></ul><ul><ul><li>SAML </li></ul></ul><ul><ul><li>Athens </li></ul></ul>
    7. 7. Athens At the simplest level, Classic Athens is a managed directory of usernames with librarian focussed tools to manage them. Over 300 premium content vendors of subscription material on the web recognise Athens usernames to allocate rights to their material using the Athens authentication system.
    8. 8. Athens Athens Features Administrator management of user accounts Separate admin accounts for each AZHIN member organization User customizable passwords Expiration dates On demand expiration of accounts Account creation through bulk uploads or on individual basis Vendor interaction required to provide access via Athens Permission sets control user access Customizable user groups and statistics gathering
    9. 9. Athens Other benefits Single sign-on Library 2.0. Access to state-purchased resources and local institution-purchased resources MyAthens Individualised usage figures.
    10. 10. Athens <ul><li>How it works </li></ul><ul><li>1) User logs into Athens </li></ul><ul><ul><li>Cookie is set with values identifying the user and the user’s organization </li></ul></ul><ul><li>2) User clicks on URL </li></ul><ul><ul><li>Vendor sees Athens cookie and confirms access eligibility with Athens </li></ul></ul><ul><li>3) User gets into resource </li></ul>
    11. 11. Athens How it works Log into Athens User’s Info Reads cookie Verifies Info Confirms credentials Access Granted User views resource Clicks on resource URL
    12. 12. AZHIN & Athens <ul><li>What happened? </li></ul><ul><ul><ul><li>Paul Bracke and Cheaney Seth </li></ul></ul></ul><ul><ul><ul><ul><li>Lyn Norris and a trial </li></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>MLA conference 2006 </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>The Krafty Librarian </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>An impromptu meeting... </li></ul></ul></ul></ul></ul>
    13. 13. AZHIN & Athens How it was implemented Standard Athens Access MyAthens login and resource access Resources displayed by vendor not by title Descriptions are customizable Athens toolbar My Athens
    14. 14. AZHIN & Athens How it was implemented AZHIN Customized Access Customizable AZHIN portal pages AZHIN member organizations can add their own logos and content Separate purchases displayed or accessed through the portal page Login box refers back to the page of origin for access to resources Access to journals and textbooks by title and subject
    15. 16. AZHIN & Athens
    16. 17. AZHIN & Athens Complications 1) Vendor URL variations NEJM IP access URL http://content.nejm.org NEJM Athens access URL http://auth.athensams.net/?ath_dspid=MMS&ath_returl=http %3A%2F%2Fcontent.nejm.org Commercial Title listing services require additional work on URLs as a result. 2) Displaying passwords sometimes required.
    17. 18. AZHIN & Athens Achievements Access to ALL resources Access to AZHIN Resources and individual organizational subscriptions Single off-site password access to all resources Password access that allows user customization of passwords Method of managing and expiring user accounts Statistical tools to monitor use
    18. 19. AZHIN & Athens AZHIN Home page AZHIN Self registration page MyAthens login Athens Home page ssweeny @ ebsco .com

    ×