SlideShare a Scribd company logo
May 2018 • NISO
IP Authentication for STEM e-Content Access –
Going, Going, Gone? Past, Present, and Futures
Don Hamparian
Sr. Product Manager, OCLC
IP Authentication for STEM e-Content
Access – Going, Going, Gone?
Past, Present, and Futures
Foundational Technologies Panel
Digital Libraries: Authentication, Access & Security for
Information Resources
NISO
Americas
10,938 members
in 28 countries
EMEA
4,009 members
in 72 countries
Asia Pacific
1,601 members
in 23 countries
As of 31 December 2017
A global network of libraries
Today’s Conversation
• IP authentication, past & present
• IP authentication’s challenges
• Alternative authentication & authorization methods
• Challenges and opportunities for libraries
Quick Survey
• Librarians?
• IP proxying today?
• Library IT?
• Institution IT?
• Publishers?
• Federation Operators?
IP Authentication
• Traditional Access Control Mechanism for 25 years
• Nearly all STEM publishers support it
• Libraries understand it and are comfortable with it
• Back in 2000 the topology for administration was simpler
• Still seen as easy to administer today
• Actual software to manage access is pretty straightforward
• “Silent” authentication and authorization for users
By Source (WP:NFCC#4), Fair use, https://en.wikipedia.org/w/index.php?curid=42693963
As IP authentication was being implemented
Early evolution in STEM access
Not all users were on the library/institution IP network,
so solutions to this problem sprung up:
• VPN access
• Virtual Desktop aka Citrix
• Proxy Servers aka EZproxy
All was good for many years
More recently, new challenges
• Piracy
• Disconnection of discovery from fulfillment technologies
• Native mobile apps
• Desire for more personalization at publishers web sites
• More complex network topologies
• Video and streaming content
A deeper look at piracy
• Some pirates are sophisticated, some simple
• Some are large-scale and systematic
• Some are for money, some for pirate’s principles
• Generally, attack vectors are simple:
– Steal credentials via Dictionary attacks, phishing, searching for
exposed credentials
– Spoof IP Address (more rare)
– Man in the middle attacks (more rare)
Credentials
• Mostly id/password at institutions, Some still just id(!), a
few MFA
• Not well managed by users, institutions or content
providers
• Not an IP-only problem
• Multi-factor helps significantly
• Short-lived passwords can help
• Complex passwords can help
Some solutions for these problems for IP
authentication exist, but should we be thinking
more broadly?
What identity management systems are
available for STEM access?
Introducing Shibboleth
Bright and shiny and new in 2003
• Shibboleth 1.0 introduced in 2003
• Included in implementation is the Security Assertion
Markup Language (SAML)
• Brought us web browser single sign-on
• For many years, adoption was slow and painful
• In spite of the startup pain, it was transformative
Shibboleth: much less painful today
• Preciseness Alert: Federated Identity Systems Implementing SAML
Browser SSO profile
• Easier implementation
• Many apps and publishers are “Shibbolized”
• Wide adoption at academic institutions
• Mature identity federations
• Many providers offering consulting or turnkey offerings
• Privacy preserving and controlled by institution IT
• https://www.shibboleth.net/
Some providers
Central Authentication Service (CAS)
• Introduced around 2004
• Apache 2.0 Open Source
• Originally developed at Yale, now provided by Apereo
Foundation
• Can participates in identity federations such as InCommon
• https://apereo.github.io/cas/5.2.x/index.html
Identity Federations
• Glue that Empowers SSO at the global scale
• Simpler service provider integration
• Common policies, technology, legal terms & conditions
• Normally defined at national level
OpenID Connect
• An authentication layer on top of OAuth 2.0
• Specification controlled by the OpenID Foundation
• Good mobile support (especially for Android)
• Good support for API authentication and authorization
• Adoption for STEM access at a very early point
• Traditional identity management interoperation also at a very early
point
• Academic institution adoption at a very early point
• https://openid.net/connect/
And now a short commercial break
for RA21
• RA21: Resource Access for the 21st Century
• Joint initiative of the International Association of
STM Publishers (STM) and the National Information
Standards Organization (NISO)
• Aimed at optimizing access protocols across key
stakeholder groups
• Corporate and university subscribers, libraries, software vendors,
publishers, identity federation operators, etc.
And now a short commercial break
for RA21
• Purpose: To a facilitate seamless user experience to
licensed STEM content beyond IP address recognition,
supporting usability, network security and user privacy
• https://ra21.org/
RA21 Goals
Recommend new solutions for access
strategies beyond IP recognition in joint
collaboration with software vendors, libraries,
federation operators, publishers and service
providers
RA21 Goals
• Test and improve solutions by organizing pilots in
a variety of environments
• Establish best practices and publish via the NISO
Recommended Practice process
• New: Prepare for post-project phase by identifying
potential parties to operate any necessary
centralized infrastructure
User Experience
P3W
RA21 Workstreams
2
Two technical pilots exploring different
implementation approaches
Two cross-cutting
workstreams
exploring topics
common to both
approaches
Privacy and Security
Corporate
Pilot
WAYF
Cloud
Pilot exploring needs of
corporate segment
RA21 Opportunities
RA21 needs to:
• Improve UX for the researcher – the “compelling”
factor
• Communicate the how-to’s and benefits for the
institution
• Demonstrate privacy preservation
• Have more library participation
That’s the authentication landscape
Let’s shift to libraries
What are the challenges and opportunities
in this changing landscape?
First, it's a long evolution
• RA21 is about developing patterns for adoption of
SAML/SSO
• Patterns take time to turn into production systems
• My prediction is at least a five-year window for larger
publishers
• Smaller (long-tail) publishers will take longer
• Take home: IP authentication is going to be around for a
long time - EZproxy is not going away
Second, it’s an important evolution
SAML/SSO have many advantages to the end user:
• Privacy protection more formalized
• Single sign-on through institution and publisher applications
• Website personalization adds functionality to applications
SAML/SSO have many advantages to the institution:
• Good foundation to protect student assets
• Common vocabulary and implementation patterns to draw upon
But libraries need to be planning…
or challenges and opportunities
• Does the library have the IT relationships necessary to start the
conversation?
• Does institution IT have a plan? Be ready to participate and guide
• Watch trends in the identity management space – it’s evolving too
• Don’t withdraw from the institution-level conversation about identity
management – libraries have valuable insight
• Get involved with your federation operators
• Get involved in RA21
Publishers also have work to do
• Make sure you know your libraries’ challenges and adjust
planning accordingly
• Develop success plans with your libraries
• Have compelling UX
Closing thoughts
• It’s a long migration not a hot cutover
• RA21 and implementers needs to produce compelling UX
• Libraries need to stay engaged in identity management
trends and implementation
• Libraries need to advocate for their patrons
• EZproxy is there the whole way
Questions?
Don Hamparian
Sr. Product Manager
hamparid@oclc.org

More Related Content

What's hot

What can SAML / Shibboleth do for your institution?
What can SAML / Shibboleth do for your institution? What can SAML / Shibboleth do for your institution?
What can SAML / Shibboleth do for your institution?
OpenAthens
 
Identity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy LutherIdentity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy Luther
National Information Standards Organization (NISO)
 
katz niso virtual conf feb17
katz niso virtual conf feb17katz niso virtual conf feb17
Leahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSOLeahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSO
National Information Standards Organization (NISO)
 
The infrastructure review process and aggregated results, by Rohan Slaughter
The infrastructure review process and aggregated results, by Rohan SlaughterThe infrastructure review process and aggregated results, by Rohan Slaughter
The infrastructure review process and aggregated results, by Rohan Slaughter
Jisc
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
OpenAthens
 
Contributing to the pursuit of excellence, by Caroline Cooke
Contributing to the pursuit of excellence, by Caroline CookeContributing to the pursuit of excellence, by Caroline Cooke
Contributing to the pursuit of excellence, by Caroline Cooke
Jisc
 
The Strategic Developer: a new role for Higher Education?
The Strategic Developer: a new role for Higher Education?The Strategic Developer: a new role for Higher Education?
The Strategic Developer: a new role for Higher Education?
Paul Walk
 
Greenbone vulnerability assessment - Networkshop44
Greenbone vulnerability assessment  - Networkshop44Greenbone vulnerability assessment  - Networkshop44
Greenbone vulnerability assessment - Networkshop44
Jisc
 
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens
 
Goans-Helms-IT Security at Georgia Tech Library
Goans-Helms-IT Security at Georgia Tech LibraryGoans-Helms-IT Security at Georgia Tech Library
Goans-Helms-IT Security at Georgia Tech Library
National Information Standards Organization (NISO)
 
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHSOpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens
 
Local, technical innovation in an outsourced world
Local, technical innovation in an outsourced worldLocal, technical innovation in an outsourced world
Local, technical innovation in an outsourced world
Paul Walk
 
From Idea to Open Source
From Idea to Open SourceFrom Idea to Open Source
From Idea to Open Source
eby
 
Organizational messenger solution
Organizational messenger solutionOrganizational messenger solution
Organizational messenger solution
Ishay Tentser
 
Webinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital JourneyWebinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital Journey
WSO2
 
Uma webinar 2014 03-20
Uma webinar 2014 03-20Uma webinar 2014 03-20
Uma webinar 2014 03-20
kantarainitiative
 
Blockchain Basics and Future Uses - Long
Blockchain Basics and Future Uses - LongBlockchain Basics and Future Uses - Long
Blockchain Basics and Future Uses - Long
Sean Manion PhD
 
Legacy system modernization: Moving to Services Platforms
Legacy system modernization: Moving to Services PlatformsLegacy system modernization: Moving to Services Platforms
Legacy system modernization: Moving to Services Platforms
Lebanese Library Association
 
Web 2 and 3
Web 2 and 3Web 2 and 3

What's hot (20)

What can SAML / Shibboleth do for your institution?
What can SAML / Shibboleth do for your institution? What can SAML / Shibboleth do for your institution?
What can SAML / Shibboleth do for your institution?
 
Identity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy LutherIdentity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy Luther
 
katz niso virtual conf feb17
katz niso virtual conf feb17katz niso virtual conf feb17
katz niso virtual conf feb17
 
Leahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSOLeahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSO
 
The infrastructure review process and aggregated results, by Rohan Slaughter
The infrastructure review process and aggregated results, by Rohan SlaughterThe infrastructure review process and aggregated results, by Rohan Slaughter
The infrastructure review process and aggregated results, by Rohan Slaughter
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
 
Contributing to the pursuit of excellence, by Caroline Cooke
Contributing to the pursuit of excellence, by Caroline CookeContributing to the pursuit of excellence, by Caroline Cooke
Contributing to the pursuit of excellence, by Caroline Cooke
 
The Strategic Developer: a new role for Higher Education?
The Strategic Developer: a new role for Higher Education?The Strategic Developer: a new role for Higher Education?
The Strategic Developer: a new role for Higher Education?
 
Greenbone vulnerability assessment - Networkshop44
Greenbone vulnerability assessment  - Networkshop44Greenbone vulnerability assessment  - Networkshop44
Greenbone vulnerability assessment - Networkshop44
 
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
 
Goans-Helms-IT Security at Georgia Tech Library
Goans-Helms-IT Security at Georgia Tech LibraryGoans-Helms-IT Security at Georgia Tech Library
Goans-Helms-IT Security at Georgia Tech Library
 
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHSOpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
 
Local, technical innovation in an outsourced world
Local, technical innovation in an outsourced worldLocal, technical innovation in an outsourced world
Local, technical innovation in an outsourced world
 
From Idea to Open Source
From Idea to Open SourceFrom Idea to Open Source
From Idea to Open Source
 
Organizational messenger solution
Organizational messenger solutionOrganizational messenger solution
Organizational messenger solution
 
Webinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital JourneyWebinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital Journey
 
Uma webinar 2014 03-20
Uma webinar 2014 03-20Uma webinar 2014 03-20
Uma webinar 2014 03-20
 
Blockchain Basics and Future Uses - Long
Blockchain Basics and Future Uses - LongBlockchain Basics and Future Uses - Long
Blockchain Basics and Future Uses - Long
 
Legacy system modernization: Moving to Services Platforms
Legacy system modernization: Moving to Services PlatformsLegacy system modernization: Moving to Services Platforms
Legacy system modernization: Moving to Services Platforms
 
Web 2 and 3
Web 2 and 3Web 2 and 3
Web 2 and 3
 

Similar to Hamparian - IP Authentication for STEM e-Content Access

RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation
National Information Standards Organization (NISO)
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG: connecting the knowledge community
 
RA21: An Update on RA21
RA21: An Update on RA21RA21: An Update on RA21
NISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateNISO-STM RA21 Project Update
NISO-STM RA21 Project Update
TACNISO
 
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
Cheryl McKinnon
 
Chris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentationChris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentation
National Information Standards Organization (NISO)
 
Digital Preservation - Manage and Provide Access
Digital Preservation - Manage and Provide AccessDigital Preservation - Manage and Provide Access
Digital Preservation - Manage and Provide Access
MichaelPaulmeno
 
Practical Steps to Address Piracy
Practical Steps to Address PiracyPractical Steps to Address Piracy
Practical Steps to Address Piracy
Chris Shillum
 
Implementing koha at iima
Implementing koha at iimaImplementing koha at iima
Implementing koha at iima
H Anil Kumar
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
OpenAthens
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptx
irfanullahkhan64
 
Building and Deploying a Global Intranet with Liferay
Building and Deploying a Global Intranet with LiferayBuilding and Deploying a Global Intranet with Liferay
Building and Deploying a Global Intranet with Liferay
rivetlogic
 
Community in a box
Community in a boxCommunity in a box
Community in a box
Mandi Walls
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
OpenAthens
 
Software management plans in research software
Software management plans in research softwareSoftware management plans in research software
Software management plans in research software
Shoaib Sufi
 
Social intranet content management by Toby Ward
Social intranet content management by Toby WardSocial intranet content management by Toby Ward
Social intranet content management by Toby Ward
Prescient Digital Media
 
Content Strategy From the Outside In
Content Strategy From the Outside InContent Strategy From the Outside In
Content Strategy From the Outside In
Chip Gettinger
 
Open Source: What is It?
Open Source: What is It?Open Source: What is It?
Open Source: What is It?
DuraSpace
 
Lessons from the front line: Next generation knowledge management using socia...
Lessons from the front line: Next generation knowledge management using socia...Lessons from the front line: Next generation knowledge management using socia...
Lessons from the front line: Next generation knowledge management using socia...
Velrada
 
Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17
Nancy Wilkins-Diehr
 

Similar to Hamparian - IP Authentication for STEM e-Content Access (20)

RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
 
RA21: An Update on RA21
RA21: An Update on RA21RA21: An Update on RA21
RA21: An Update on RA21
 
NISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateNISO-STM RA21 Project Update
NISO-STM RA21 Project Update
 
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
 
Chris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentationChris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentation
 
Digital Preservation - Manage and Provide Access
Digital Preservation - Manage and Provide AccessDigital Preservation - Manage and Provide Access
Digital Preservation - Manage and Provide Access
 
Practical Steps to Address Piracy
Practical Steps to Address PiracyPractical Steps to Address Piracy
Practical Steps to Address Piracy
 
Implementing koha at iima
Implementing koha at iimaImplementing koha at iima
Implementing koha at iima
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptx
 
Building and Deploying a Global Intranet with Liferay
Building and Deploying a Global Intranet with LiferayBuilding and Deploying a Global Intranet with Liferay
Building and Deploying a Global Intranet with Liferay
 
Community in a box
Community in a boxCommunity in a box
Community in a box
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
 
Software management plans in research software
Software management plans in research softwareSoftware management plans in research software
Software management plans in research software
 
Social intranet content management by Toby Ward
Social intranet content management by Toby WardSocial intranet content management by Toby Ward
Social intranet content management by Toby Ward
 
Content Strategy From the Outside In
Content Strategy From the Outside InContent Strategy From the Outside In
Content Strategy From the Outside In
 
Open Source: What is It?
Open Source: What is It?Open Source: What is It?
Open Source: What is It?
 
Lessons from the front line: Next generation knowledge management using socia...
Lessons from the front line: Next generation knowledge management using socia...Lessons from the front line: Next generation knowledge management using socia...
Lessons from the front line: Next generation knowledge management using socia...
 
Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17
 

More from National Information Standards Organization (NISO)

Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
National Information Standards Organization (NISO)
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
National Information Standards Organization (NISO)
 
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
National Information Standards Organization (NISO)
 
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
National Information Standards Organization (NISO)
 
Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
National Information Standards Organization (NISO)
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
National Information Standards Organization (NISO)
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
National Information Standards Organization (NISO)
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
National Information Standards Organization (NISO)
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
National Information Standards Organization (NISO)
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
National Information Standards Organization (NISO)
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
National Information Standards Organization (NISO)
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
National Information Standards Organization (NISO)
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
National Information Standards Organization (NISO)
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
National Information Standards Organization (NISO)
 

More from National Information Standards Organization (NISO) (20)

Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
 
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
 
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
 
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
 
Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"
 
Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
 

Recently uploaded

Hindi varnamala | hindi alphabet PPT.pdf
Hindi varnamala | hindi alphabet PPT.pdfHindi varnamala | hindi alphabet PPT.pdf
Hindi varnamala | hindi alphabet PPT.pdf
Dr. Mulla Adam Ali
 
MARY JANE WILSON, A “BOA MÃE” .
MARY JANE WILSON, A “BOA MÃE”           .MARY JANE WILSON, A “BOA MÃE”           .
MARY JANE WILSON, A “BOA MÃE” .
Colégio Santa Teresinha
 
PIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf IslamabadPIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf Islamabad
AyyanKhan40
 
How to Fix the Import Error in the Odoo 17
How to Fix the Import Error in the Odoo 17How to Fix the Import Error in the Odoo 17
How to Fix the Import Error in the Odoo 17
Celine George
 
The basics of sentences session 6pptx.pptx
The basics of sentences session 6pptx.pptxThe basics of sentences session 6pptx.pptx
The basics of sentences session 6pptx.pptx
heathfieldcps1
 
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdfANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
Priyankaranawat4
 
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdfবাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
eBook.com.bd (প্রয়োজনীয় বাংলা বই)
 
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptxPrésentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
siemaillard
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
GeorgeMilliken2
 
The History of Stoke Newington Street Names
The History of Stoke Newington Street NamesThe History of Stoke Newington Street Names
The History of Stoke Newington Street Names
History of Stoke Newington
 
Film vocab for eal 3 students: Australia the movie
Film vocab for eal 3 students: Australia the movieFilm vocab for eal 3 students: Australia the movie
Film vocab for eal 3 students: Australia the movie
Nicholas Montgomery
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
iammrhaywood
 
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UPLAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
RAHUL
 
How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17
Celine George
 
Cognitive Development Adolescence Psychology
Cognitive Development Adolescence PsychologyCognitive Development Adolescence Psychology
Cognitive Development Adolescence Psychology
paigestewart1632
 
Advanced Java[Extra Concepts, Not Difficult].docx
Advanced Java[Extra Concepts, Not Difficult].docxAdvanced Java[Extra Concepts, Not Difficult].docx
Advanced Java[Extra Concepts, Not Difficult].docx
adhitya5119
 
Wound healing PPT
Wound healing PPTWound healing PPT
Wound healing PPT
Jyoti Chand
 
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem studentsRHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
Himanshu Rai
 
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
PECB
 
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching AptitudeUGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
S. Raj Kumar
 

Recently uploaded (20)

Hindi varnamala | hindi alphabet PPT.pdf
Hindi varnamala | hindi alphabet PPT.pdfHindi varnamala | hindi alphabet PPT.pdf
Hindi varnamala | hindi alphabet PPT.pdf
 
MARY JANE WILSON, A “BOA MÃE” .
MARY JANE WILSON, A “BOA MÃE”           .MARY JANE WILSON, A “BOA MÃE”           .
MARY JANE WILSON, A “BOA MÃE” .
 
PIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf IslamabadPIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf Islamabad
 
How to Fix the Import Error in the Odoo 17
How to Fix the Import Error in the Odoo 17How to Fix the Import Error in the Odoo 17
How to Fix the Import Error in the Odoo 17
 
The basics of sentences session 6pptx.pptx
The basics of sentences session 6pptx.pptxThe basics of sentences session 6pptx.pptx
The basics of sentences session 6pptx.pptx
 
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdfANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
 
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdfবাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
বাংলাদেশ অর্থনৈতিক সমীক্ষা (Economic Review) ২০২৪ UJS App.pdf
 
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptxPrésentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
 
The History of Stoke Newington Street Names
The History of Stoke Newington Street NamesThe History of Stoke Newington Street Names
The History of Stoke Newington Street Names
 
Film vocab for eal 3 students: Australia the movie
Film vocab for eal 3 students: Australia the movieFilm vocab for eal 3 students: Australia the movie
Film vocab for eal 3 students: Australia the movie
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
 
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UPLAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
 
How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17
 
Cognitive Development Adolescence Psychology
Cognitive Development Adolescence PsychologyCognitive Development Adolescence Psychology
Cognitive Development Adolescence Psychology
 
Advanced Java[Extra Concepts, Not Difficult].docx
Advanced Java[Extra Concepts, Not Difficult].docxAdvanced Java[Extra Concepts, Not Difficult].docx
Advanced Java[Extra Concepts, Not Difficult].docx
 
Wound healing PPT
Wound healing PPTWound healing PPT
Wound healing PPT
 
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem studentsRHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
 
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
 
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching AptitudeUGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
 

Hamparian - IP Authentication for STEM e-Content Access

  • 1. May 2018 • NISO IP Authentication for STEM e-Content Access – Going, Going, Gone? Past, Present, and Futures Don Hamparian Sr. Product Manager, OCLC
  • 2. IP Authentication for STEM e-Content Access – Going, Going, Gone? Past, Present, and Futures Foundational Technologies Panel Digital Libraries: Authentication, Access & Security for Information Resources NISO
  • 3. Americas 10,938 members in 28 countries EMEA 4,009 members in 72 countries Asia Pacific 1,601 members in 23 countries As of 31 December 2017 A global network of libraries
  • 4.
  • 5. Today’s Conversation • IP authentication, past & present • IP authentication’s challenges • Alternative authentication & authorization methods • Challenges and opportunities for libraries
  • 6. Quick Survey • Librarians? • IP proxying today? • Library IT? • Institution IT? • Publishers? • Federation Operators?
  • 7. IP Authentication • Traditional Access Control Mechanism for 25 years • Nearly all STEM publishers support it • Libraries understand it and are comfortable with it • Back in 2000 the topology for administration was simpler • Still seen as easy to administer today • Actual software to manage access is pretty straightforward • “Silent” authentication and authorization for users
  • 8. By Source (WP:NFCC#4), Fair use, https://en.wikipedia.org/w/index.php?curid=42693963 As IP authentication was being implemented
  • 9. Early evolution in STEM access Not all users were on the library/institution IP network, so solutions to this problem sprung up: • VPN access • Virtual Desktop aka Citrix • Proxy Servers aka EZproxy All was good for many years
  • 10. More recently, new challenges • Piracy • Disconnection of discovery from fulfillment technologies • Native mobile apps • Desire for more personalization at publishers web sites • More complex network topologies • Video and streaming content
  • 11. A deeper look at piracy • Some pirates are sophisticated, some simple • Some are large-scale and systematic • Some are for money, some for pirate’s principles • Generally, attack vectors are simple: – Steal credentials via Dictionary attacks, phishing, searching for exposed credentials – Spoof IP Address (more rare) – Man in the middle attacks (more rare)
  • 12. Credentials • Mostly id/password at institutions, Some still just id(!), a few MFA • Not well managed by users, institutions or content providers • Not an IP-only problem • Multi-factor helps significantly • Short-lived passwords can help • Complex passwords can help
  • 13. Some solutions for these problems for IP authentication exist, but should we be thinking more broadly? What identity management systems are available for STEM access?
  • 14. Introducing Shibboleth Bright and shiny and new in 2003 • Shibboleth 1.0 introduced in 2003 • Included in implementation is the Security Assertion Markup Language (SAML) • Brought us web browser single sign-on • For many years, adoption was slow and painful • In spite of the startup pain, it was transformative
  • 15. Shibboleth: much less painful today • Preciseness Alert: Federated Identity Systems Implementing SAML Browser SSO profile • Easier implementation • Many apps and publishers are “Shibbolized” • Wide adoption at academic institutions • Mature identity federations • Many providers offering consulting or turnkey offerings • Privacy preserving and controlled by institution IT • https://www.shibboleth.net/
  • 17. Central Authentication Service (CAS) • Introduced around 2004 • Apache 2.0 Open Source • Originally developed at Yale, now provided by Apereo Foundation • Can participates in identity federations such as InCommon • https://apereo.github.io/cas/5.2.x/index.html
  • 18. Identity Federations • Glue that Empowers SSO at the global scale • Simpler service provider integration • Common policies, technology, legal terms & conditions • Normally defined at national level
  • 19. OpenID Connect • An authentication layer on top of OAuth 2.0 • Specification controlled by the OpenID Foundation • Good mobile support (especially for Android) • Good support for API authentication and authorization • Adoption for STEM access at a very early point • Traditional identity management interoperation also at a very early point • Academic institution adoption at a very early point • https://openid.net/connect/
  • 20. And now a short commercial break for RA21 • RA21: Resource Access for the 21st Century • Joint initiative of the International Association of STM Publishers (STM) and the National Information Standards Organization (NISO) • Aimed at optimizing access protocols across key stakeholder groups • Corporate and university subscribers, libraries, software vendors, publishers, identity federation operators, etc.
  • 21. And now a short commercial break for RA21 • Purpose: To a facilitate seamless user experience to licensed STEM content beyond IP address recognition, supporting usability, network security and user privacy • https://ra21.org/
  • 22. RA21 Goals Recommend new solutions for access strategies beyond IP recognition in joint collaboration with software vendors, libraries, federation operators, publishers and service providers
  • 23. RA21 Goals • Test and improve solutions by organizing pilots in a variety of environments • Establish best practices and publish via the NISO Recommended Practice process • New: Prepare for post-project phase by identifying potential parties to operate any necessary centralized infrastructure
  • 24. User Experience P3W RA21 Workstreams 2 Two technical pilots exploring different implementation approaches Two cross-cutting workstreams exploring topics common to both approaches Privacy and Security Corporate Pilot WAYF Cloud Pilot exploring needs of corporate segment
  • 25. RA21 Opportunities RA21 needs to: • Improve UX for the researcher – the “compelling” factor • Communicate the how-to’s and benefits for the institution • Demonstrate privacy preservation • Have more library participation
  • 26. That’s the authentication landscape Let’s shift to libraries What are the challenges and opportunities in this changing landscape?
  • 27. First, it's a long evolution • RA21 is about developing patterns for adoption of SAML/SSO • Patterns take time to turn into production systems • My prediction is at least a five-year window for larger publishers • Smaller (long-tail) publishers will take longer • Take home: IP authentication is going to be around for a long time - EZproxy is not going away
  • 28. Second, it’s an important evolution SAML/SSO have many advantages to the end user: • Privacy protection more formalized • Single sign-on through institution and publisher applications • Website personalization adds functionality to applications SAML/SSO have many advantages to the institution: • Good foundation to protect student assets • Common vocabulary and implementation patterns to draw upon
  • 29. But libraries need to be planning… or challenges and opportunities • Does the library have the IT relationships necessary to start the conversation? • Does institution IT have a plan? Be ready to participate and guide • Watch trends in the identity management space – it’s evolving too • Don’t withdraw from the institution-level conversation about identity management – libraries have valuable insight • Get involved with your federation operators • Get involved in RA21
  • 30. Publishers also have work to do • Make sure you know your libraries’ challenges and adjust planning accordingly • Develop success plans with your libraries • Have compelling UX
  • 31. Closing thoughts • It’s a long migration not a hot cutover • RA21 and implementers needs to produce compelling UX • Libraries need to stay engaged in identity management trends and implementation • Libraries need to advocate for their patrons • EZproxy is there the whole way
  • 32. Questions? Don Hamparian Sr. Product Manager hamparid@oclc.org