SlideShare a Scribd company logo
1 of 37
openathens.org
Preserving user privacy and protecting online
content
Adam Snook
Product manager
openathens.org
Please use the ‘Raise your hand’
button, found on your control panel,
to indicate that you can hear the
audio
openathens.org
To ask our speakers a question, please enter them here
openathens.org
Preserving user privacy and protecting online
content
Adam Snook
Product manager
Webinar - 27 February 2019
openathens.org
What we’ll cover
What is federated single sign-on?
How can it preserve user privacy?
How it protects valuable subscribed content?
What is the future of access to online
information?
More information and next steps
openathens.org
What is federated single sign-on?
Adam Snook
Product manager
openathens.org
What is federated
single sign-on?
Three-way trust relationship between a library user, their
organisation and content provider
Organisation manages user consent and authentication
Content provider manages access rights and authorisation of
access to content
OpenAthens provides the eco-system where encrypted user attributes are
exchanged between organisation and content provider, securely and seamlessly
Webopedia definition
Federated Access
Service ProvidersIdentity Providers
Providing the user’s identity. I.e.
their email address and
subscribed resources.
Providing paid-for content to
organisations and their users.Authentication vs Authorisation
“We confirm this user
is a student from our
Biology department”
“Biology students from your
institution can only access our
Biology content”
attributes
SAML ‘Handshake’
openathens.org
Preserving user privacy
openathens.org
openathens.org
Data Protection Code of Conduct
• Service providers must comply with data protection legislation
• Supported by RA21, the Code of Conduct principles include:
o Minimising the attribute data released to service providers
o Restricting attribute data to enabling access, unless user consent has been obtained
(directly or via the user’s organisation)
o Deleting/anonymising attribute data when no longer necessary
o No transfer of attribute data to another service, except if mandated for enabling
access on behalf of the service provider, the third party also complies with data
protection, and prior user consent is obtained
o Security measures to safeguard user attributes
• bit.ly/GEANTdp
openathens.org
How does OpenAthens handle privacy?
Our privacy statement:
• What information we collect
• What we do with that information
• How we protect it
• How long we keep it for
• How you can check your information
• openathens.org/privacy/
openathens.org
Library organisations - your responsibilities
• Processing of user data must be fair, lawful, necessary and proportionate to the
purpose(s) for which data is required.
• Organisations must inform users what their personal data will be used for at the time it is
collected.
• Users can ‘opt out’ of providing personally identifiable information.
• Organisations must ensure personal data is not misused and only released to service
providers when necessary.
• User consent may be requested for additional personal data. Users can change their
minds and change or stop future release of this information.
openathens.org
Privacy challenges for librarians
• Blog: Opportunities and challenges for
librarians created by technology
• EBSCO long overdue podcast
“Some providers have gone so far
as to provide personalisation
without using any personally
identifiable information
whatsoever.”
openathens.org
Protecting privacy through user attributes
Attribute Description
eduPersonScopedAffiliation User’s association with the organisation e.g. student,
researcher, staff, alumni, walk-in, affiliate
eduPersonTargetedID An opaque, persistent and pseudonymous identifier
used for personalisation. Unique to each user, it does
not contain any information that can identify a person.
eduPersonEntitlement Describes the resource set the user is entitled to
access.
openathens.org
User managed consent
• Users can accept release of
attributes to service providers using
Shibboleth Identity Provider v3
• Attributes may include
eduPersonPrincipalName
• Openathens plans to support
user managed consent and multi-
factor authentication in the future
openathens.org
Protecting content
openathens.org
IP-based access
• Sometimes results in users providing personal information to publishers
• Difficult to track who your users are
• Inconsistent user journey off-site, so users choose the easy route e.g.
sharing content with friends or colleagues, or access via pre-print
repositories, ResearchGate and SciHub
• Fewer visits to your website potentially impacts library subscription decisions
openathens.org
Federated single sign-on
• Trust model – more secure
• Users less likely to share their credentials
• Library verifies who the user is
• You trust the library
• Seamless user journey to all the library’s subscribed content
• Users less likely to visit other nefarious sites
• Can request personally identifiable information from users with their consent
e.g. eduPersonPrincipalName
openathens.org
OpenAthens Conference, 19 March 2019, London
Panel debate: Piracy as a disruptor for
change
Further reading:
How piracy is forcing industry
transformation
Emily Powell, College of Policing Phil Leahy, OpenAthens
Date
SIMPLE, TRUSTED ACCESS –
ANYWHERE, ANYTIME, ON ANY DEVICE
www.ra21.org
openathens.org
What is RA21?
• Resource Access for the 21st Century (RA21) is a joint STM and NISO initiative
with goals to:
o Facilitate a seamless user experience for consumers of scientific
communication.
o Solve long standing and complex challenges in the areas of network
security and user privacy.
• Universal agreement that there needs to be alternatives to IP authentication.
• Aiming for adoption of RA21 recommendations globally.
openathens.org
Myth Busting: Five Commonly
Held Misconceptions About
RA21 (and One Rumor
Confirmed)
UX Building Blocks
2
Consistent visual cue
and call to action signals
institutional access
Flexible and smart search
• Search by institution name,
abbreviation or email
• Typeahead matching and URL
Remembered institution
on next access1 2 3
RA21 UX Goals
2
A user only encounters a
discovery process once
(per browser).
The user’s institution is persisted
in browser local storage and
subsequently rendered in the
RA21 button across all
participating publishers.
1 2
openathens.org
Main outputs
1. Set of recommendations that build on NISO’s ESSPReSSO recommended
practice
2. Establish a new governance structure
3. Launch a new service that simplifies access for users
Main outcome
• Expectation that publishers will start to deploy RA21 recommended practices in
second half of 2019.
openathens.org
OpenAthens Conference, 19 March 2019, London
Guest blog: Todd Carpenter, NISO
outlines the work of RA21 to simplify
access
openathens.org
Simplifying access with
OpenAthens Wayfinder
openathens.org
Example of a poor user journey
openathens.org
Wayfinder
openathens.org
What data does the publisher see?
openathens.org
Wayfinder
development
Embeddable and pop-up versions on their
way
Help us to develop Wayfinder
Feedback on integration and new features
contact@openathens.net
openathens.org
Questions?Q&A – over to you
openathens.org
More information
Adam Snook
adam.snook@openathens.net
Product manager
openathens.org
• Download the free ebook which includes
explanations and guides on:
• The difference between authentication and
authorisation
• Web based authentication
• IP address recognition
• What SAML is and how it works
• OpenID Connect
• Basic troubleshooting
openathens.org
This report presents the key findings from
over 900 responses including:
• Access management is critical to meeting
users needs
• Increased demand for mobile or off-site
access
• Library staff requiring greater technical
expertise than ever before
• The need to help users with their digital
skills
openathens.org

More Related Content

What's hot

web 1.0, 2.0, 3.0
web 1.0, 2.0, 3.0 web 1.0, 2.0, 3.0
web 1.0, 2.0, 3.0 Nonie Mislan
 
What is Web 3.0?
What is Web 3.0?What is Web 3.0?
What is Web 3.0?Johan Koren
 
Web 3.0 (Presentation)
Web 3.0 (Presentation)Web 3.0 (Presentation)
Web 3.0 (Presentation)Allan Cho
 
Organise your life and create frameworks with a digital library (schoolnetsa11)
Organise your life and create frameworks with a digital library (schoolnetsa11)Organise your life and create frameworks with a digital library (schoolnetsa11)
Organise your life and create frameworks with a digital library (schoolnetsa11)Maggie Verster
 
Library 2.0 And Web 2.0
Library 2.0 And Web 2.0Library 2.0 And Web 2.0
Library 2.0 And Web 2.0Joyjoy
 
Emerging Trends and Technologies
Emerging Trends and TechnologiesEmerging Trends and Technologies
Emerging Trends and TechnologiesScott Abel
 
What is internet
What is internetWhat is internet
What is internetcramars
 
The Web: history - now - future
The Web: history - now - futureThe Web: history - now - future
The Web: history - now - futureKnowledge Hives
 

What's hot (11)

web 1.0, 2.0, 3.0
web 1.0, 2.0, 3.0 web 1.0, 2.0, 3.0
web 1.0, 2.0, 3.0
 
What is Web 3.0?
What is Web 3.0?What is Web 3.0?
What is Web 3.0?
 
Web 3.0 (Presentation)
Web 3.0 (Presentation)Web 3.0 (Presentation)
Web 3.0 (Presentation)
 
Organise your life and create frameworks with a digital library (schoolnetsa11)
Organise your life and create frameworks with a digital library (schoolnetsa11)Organise your life and create frameworks with a digital library (schoolnetsa11)
Organise your life and create frameworks with a digital library (schoolnetsa11)
 
Library 2.0 And Web 2.0
Library 2.0 And Web 2.0Library 2.0 And Web 2.0
Library 2.0 And Web 2.0
 
Why Web 2.0?
Why Web 2.0?Why Web 2.0?
Why Web 2.0?
 
Hyperlinks
HyperlinksHyperlinks
Hyperlinks
 
Internet Privacy
Internet PrivacyInternet Privacy
Internet Privacy
 
Emerging Trends and Technologies
Emerging Trends and TechnologiesEmerging Trends and Technologies
Emerging Trends and Technologies
 
What is internet
What is internetWhat is internet
What is internet
 
The Web: history - now - future
The Web: history - now - futureThe Web: history - now - future
The Web: history - now - future
 

Similar to Webinar: Preserving user privacy and protecting online content

Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarOpenAthens
 
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens
 
Jon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
Jon Bentley - UK federation & Shibboleth Consortium Publisher MeetingJon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
Jon Bentley - UK federation & Shibboleth Consortium Publisher MeetingOpenAthens
 
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens
 
COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)CASRAI
 
GALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnershipGALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnershipOpenAthens
 
SHARE Notification Service, December 2014
SHARE Notification Service, December 2014SHARE Notification Service, December 2014
SHARE Notification Service, December 2014SHARE
 
OpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens
 
Evaluation of Web Scale Discovery Services
Evaluation of Web Scale Discovery ServicesEvaluation of Web Scale Discovery Services
Evaluation of Web Scale Discovery ServicesNikesh Narayanan
 
12.10.14 Slides, “The SHARE Notification Service”
12.10.14 Slides, “The SHARE Notification Service”12.10.14 Slides, “The SHARE Notification Service”
12.10.14 Slides, “The SHARE Notification Service”DuraSpace
 
NISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateNISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateTACNISO
 
Introducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providersIntroducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providersOpenAthens
 

Similar to Webinar: Preserving user privacy and protecting online content (20)

Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
 
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
 
Jon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
Jon Bentley - UK federation & Shibboleth Consortium Publisher MeetingJon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
Jon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
 
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
 
RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation
 
COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)
 
GALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnershipGALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnership
 
ALA NISO-BISG Forum - Patron Privacy
ALA NISO-BISG Forum - Patron PrivacyALA NISO-BISG Forum - Patron Privacy
ALA NISO-BISG Forum - Patron Privacy
 
SHARE Notification Service, December 2014
SHARE Notification Service, December 2014SHARE Notification Service, December 2014
SHARE Notification Service, December 2014
 
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
 
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
 
RA21 and Privacy - NISO ALA Annual 2018
RA21 and Privacy - NISO ALA Annual 2018RA21 and Privacy - NISO ALA Annual 2018
RA21 and Privacy - NISO ALA Annual 2018
 
Patham "NISO-ODI (Open Discovery Initiative) Standards Update"
Patham "NISO-ODI (Open Discovery Initiative) Standards Update"Patham "NISO-ODI (Open Discovery Initiative) Standards Update"
Patham "NISO-ODI (Open Discovery Initiative) Standards Update"
 
OpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital content
 
Evaluation of Web Scale Discovery Services
Evaluation of Web Scale Discovery ServicesEvaluation of Web Scale Discovery Services
Evaluation of Web Scale Discovery Services
 
12.10.14 Slides, “The SHARE Notification Service”
12.10.14 Slides, “The SHARE Notification Service”12.10.14 Slides, “The SHARE Notification Service”
12.10.14 Slides, “The SHARE Notification Service”
 
NISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateNISO-STM RA21 Project Update
NISO-STM RA21 Project Update
 
NISO April 30th RA21 Webinar
NISO April 30th RA21 WebinarNISO April 30th RA21 Webinar
NISO April 30th RA21 Webinar
 
Introducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providersIntroducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providers
 
The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?
 

More from OpenAthens

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxOpenAthens
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeOpenAthens
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...OpenAthens
 
What is federated single sign-on?
What is federated single sign-on?What is federated single sign-on?
What is federated single sign-on?OpenAthens
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessOpenAthens
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccessOpenAthens
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeOpenAthens
 
Access Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integrationAccess Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integrationOpenAthens
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapOpenAthens
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationOpenAthens
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensOpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...OpenAthens
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsOpenAthens
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooOpenAthens
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...OpenAthens
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? OpenAthens
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereOpenAthens
 
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...OpenAthens
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterOpenAthens
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesOpenAthens
 

More from OpenAthens (20)

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptx
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledge
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
 
What is federated single sign-on?
What is federated single sign-on?What is federated single sign-on?
What is federated single sign-on?
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccess
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledge
 
Access Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integrationAccess Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integration
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmap
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementation
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital products
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users too
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation?
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhere
 
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charter
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge services
 

Recently uploaded

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 

Recently uploaded (20)

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 

Webinar: Preserving user privacy and protecting online content

  • 1. openathens.org Preserving user privacy and protecting online content Adam Snook Product manager
  • 2. openathens.org Please use the ‘Raise your hand’ button, found on your control panel, to indicate that you can hear the audio
  • 3. openathens.org To ask our speakers a question, please enter them here
  • 4. openathens.org Preserving user privacy and protecting online content Adam Snook Product manager Webinar - 27 February 2019
  • 5. openathens.org What we’ll cover What is federated single sign-on? How can it preserve user privacy? How it protects valuable subscribed content? What is the future of access to online information? More information and next steps
  • 6. openathens.org What is federated single sign-on? Adam Snook Product manager
  • 7. openathens.org What is federated single sign-on? Three-way trust relationship between a library user, their organisation and content provider Organisation manages user consent and authentication Content provider manages access rights and authorisation of access to content OpenAthens provides the eco-system where encrypted user attributes are exchanged between organisation and content provider, securely and seamlessly Webopedia definition
  • 8. Federated Access Service ProvidersIdentity Providers Providing the user’s identity. I.e. their email address and subscribed resources. Providing paid-for content to organisations and their users.Authentication vs Authorisation “We confirm this user is a student from our Biology department” “Biology students from your institution can only access our Biology content” attributes SAML ‘Handshake’
  • 11. openathens.org Data Protection Code of Conduct • Service providers must comply with data protection legislation • Supported by RA21, the Code of Conduct principles include: o Minimising the attribute data released to service providers o Restricting attribute data to enabling access, unless user consent has been obtained (directly or via the user’s organisation) o Deleting/anonymising attribute data when no longer necessary o No transfer of attribute data to another service, except if mandated for enabling access on behalf of the service provider, the third party also complies with data protection, and prior user consent is obtained o Security measures to safeguard user attributes • bit.ly/GEANTdp
  • 12. openathens.org How does OpenAthens handle privacy? Our privacy statement: • What information we collect • What we do with that information • How we protect it • How long we keep it for • How you can check your information • openathens.org/privacy/
  • 13. openathens.org Library organisations - your responsibilities • Processing of user data must be fair, lawful, necessary and proportionate to the purpose(s) for which data is required. • Organisations must inform users what their personal data will be used for at the time it is collected. • Users can ‘opt out’ of providing personally identifiable information. • Organisations must ensure personal data is not misused and only released to service providers when necessary. • User consent may be requested for additional personal data. Users can change their minds and change or stop future release of this information.
  • 14. openathens.org Privacy challenges for librarians • Blog: Opportunities and challenges for librarians created by technology • EBSCO long overdue podcast “Some providers have gone so far as to provide personalisation without using any personally identifiable information whatsoever.”
  • 15. openathens.org Protecting privacy through user attributes Attribute Description eduPersonScopedAffiliation User’s association with the organisation e.g. student, researcher, staff, alumni, walk-in, affiliate eduPersonTargetedID An opaque, persistent and pseudonymous identifier used for personalisation. Unique to each user, it does not contain any information that can identify a person. eduPersonEntitlement Describes the resource set the user is entitled to access.
  • 16. openathens.org User managed consent • Users can accept release of attributes to service providers using Shibboleth Identity Provider v3 • Attributes may include eduPersonPrincipalName • Openathens plans to support user managed consent and multi- factor authentication in the future
  • 18. openathens.org IP-based access • Sometimes results in users providing personal information to publishers • Difficult to track who your users are • Inconsistent user journey off-site, so users choose the easy route e.g. sharing content with friends or colleagues, or access via pre-print repositories, ResearchGate and SciHub • Fewer visits to your website potentially impacts library subscription decisions
  • 19. openathens.org Federated single sign-on • Trust model – more secure • Users less likely to share their credentials • Library verifies who the user is • You trust the library • Seamless user journey to all the library’s subscribed content • Users less likely to visit other nefarious sites • Can request personally identifiable information from users with their consent e.g. eduPersonPrincipalName
  • 20. openathens.org OpenAthens Conference, 19 March 2019, London Panel debate: Piracy as a disruptor for change Further reading: How piracy is forcing industry transformation Emily Powell, College of Policing Phil Leahy, OpenAthens
  • 21. Date SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY DEVICE www.ra21.org
  • 22. openathens.org What is RA21? • Resource Access for the 21st Century (RA21) is a joint STM and NISO initiative with goals to: o Facilitate a seamless user experience for consumers of scientific communication. o Solve long standing and complex challenges in the areas of network security and user privacy. • Universal agreement that there needs to be alternatives to IP authentication. • Aiming for adoption of RA21 recommendations globally.
  • 23. openathens.org Myth Busting: Five Commonly Held Misconceptions About RA21 (and One Rumor Confirmed)
  • 24. UX Building Blocks 2 Consistent visual cue and call to action signals institutional access Flexible and smart search • Search by institution name, abbreviation or email • Typeahead matching and URL Remembered institution on next access1 2 3
  • 25. RA21 UX Goals 2 A user only encounters a discovery process once (per browser). The user’s institution is persisted in browser local storage and subsequently rendered in the RA21 button across all participating publishers. 1 2
  • 26. openathens.org Main outputs 1. Set of recommendations that build on NISO’s ESSPReSSO recommended practice 2. Establish a new governance structure 3. Launch a new service that simplifies access for users Main outcome • Expectation that publishers will start to deploy RA21 recommended practices in second half of 2019.
  • 27. openathens.org OpenAthens Conference, 19 March 2019, London Guest blog: Todd Carpenter, NISO outlines the work of RA21 to simplify access
  • 29. openathens.org Example of a poor user journey
  • 31. openathens.org What data does the publisher see?
  • 32. openathens.org Wayfinder development Embeddable and pop-up versions on their way Help us to develop Wayfinder Feedback on integration and new features contact@openathens.net
  • 35. openathens.org • Download the free ebook which includes explanations and guides on: • The difference between authentication and authorisation • Web based authentication • IP address recognition • What SAML is and how it works • OpenID Connect • Basic troubleshooting
  • 36. openathens.org This report presents the key findings from over 900 responses including: • Access management is critical to meeting users needs • Increased demand for mobile or off-site access • Library staff requiring greater technical expertise than ever before • The need to help users with their digital skills

Editor's Notes

  1. Pan-European network for research & education. Must have sec measures in place to safeguard Opaque identifiers are allowed for the purpose of recognising a returning user, but not their individual identity
  2. iso27001
  3. Myth 1: IP authentication is privacy preserving, where federated authentication technologies are not. BUSTED Myth 2: Proxy servers work just fine as a solution for off-campus access. BUSTED Myth 3: RA21 wants to enable publishers to track users across each other’s platforms. BUSTED Myth 4: RA21 creates yet another username and password. BUSTED Myth 5: RA21 is placing control of users’ identity in the hands of institutions and not the individuals themselves. PLAUSIBLE Myth 6: RA21 seeks to eliminate IP-based access. CONFIRMED
  4. Ralph
  5. Ralph