SlideShare a Scribd company logo
1 of 21
Let’s Talk About Privacy and RA21
Todd Carpenter, Executive Director, National Information Standards Organization (NISO)
Dan Ayala, CISO & Privacy Officer, ProQuest
Andrew Anderson, President, Library and Information Resources Network, Inc.
NISO RA21 ALA Annual Conference
June 24, 2018
Some Context about RA21
Behind the scenes:
Does the user have
access rights?
Yes or No?
Do you have a login?
Yes or No?
Where are you from?
??????
An Analogy: Credit card processing
Excuse me. To process this payment you need to tell me: What is the
payment processing clearinghouse your bank uses?
And patrons are just getting annoyed
RA21 wants to build on the user
experience of the wider web
Make the login experience match the user
experience we’re all familiar with
Private Experience Target Institutional Experience
How SAML Can Protect Privacy
Publishers receive
attributes about the
user, not the user’s
identity.
RA21 Pilots
• Corporate Pilot (Universal Resrource Access “URA”)
•Two Academic Pilots
– Privacy Preserving Persistent WAYF Pilot
– WAYF Cloud Pilot
All seek to address the User Experience for off-campus access
Initial Privacy Review of RA21 Pilots
SECURITY & PRIVACY RECOMMENDATIONS Cloud WAYF P3W
Privacy Policy Requirements √ √
Data Protection Impact Analysis Required √ √
Data Retention Policy Required √
Denial of Service Protection √
Browser security (https + access controls) implementations √ √
Database/data protection best practices √
Server hardening - for security threats √ √
Code Scanning - for security threats √ √
Vulnerability Scanning/Penetration Testing √ √
API security protocols √
Audit Logging and review √
Security Monitoring √
Incident Response Plan √
High Availability Infrastructure requirements √ √
Anti-virus software monitoring √ √
GDPR compliance concerns √
Privacy Preserving Persistent (P3) WAYF Pilot
•Pilot goals
– To improve current Shibboleth Identity Provider discovery process
• Incorporate additional “WAYF hints” such as email domain and IP address into
federation metadata
• Improve sign-in flow using those WAYF hints via a shared discovery service
• Populate shared discovery service hints from the Service Providers regarding
what Identity Providers are likely to work in an authorization scenario
• Enable cross-provider persistence of WAYF choice using browser local storage
•Pilot participants (confirmed so far)
Project Management
GÉANT
Educational Access Management Federations
Sunet & SWAMiD (Swedish Federation)
The samlbits.org project
eduGAIN
EduServ
Publishers
Elsevier
American Chemical Society
Subscribing institutions
MIT
University of California, Davis
University of Arizona (tbc)
University of Denver (tbc)
Service Providers
ProQuest
Ping
LibLynx
Ebsco
Preserving Privacy
Built upon ”SAML-BITS”
technology in production
Technique Challenge
Only domain part of email
address needs to be
transmitted from browser
to publisher platform to
select IDP
Need to define and test a
standardized UI that
makes this clear to users
IdP preference is stored
locally in the browser,
retrieved using centrally
served javascript, not on a
central server
Need to adapt Account
Choose mechanism to
support SAML IdPs vs
OpenID Connect
Authorization Servers
It’s Not That Scary: A Short Demo
https://www.youtube.com/watch?v=mkQC64zfNyw&feature=youtu.be
Prototype demo starts at 1:22:01 in the recording
CRITICISM OF RA21
• Yes, SciHub is a motivator of RA21, but not the
only motivator.
• This project began with outreach from LIBRARIES!
• There are a variety of
reasons why libraries
would like to improve
access control
• Evil twins? Come on….
MORE CRITICISM OF RA21
• Open Access is not the end-all be-all of library
access control issues.
– First, even if every journal article were OA, not all
content provided by libraries will be freely available
– Second, a variety of the services that libraries provide
will still need authentication, regardless of whether
they are free or not
– To presume that RA21 is a fight against open access is
to have a very narrow and dim view of what libraries
do and provide.
EVEN MORE CRITICISM OF RA21
• RA21 is a nefarious plot by publishers to hoover
up all sorts of patron data.
– First, SAML data released by identity federations is under the
control of institutions, who can set limits on what data is
released or not, it is NOT controlled by publishers
– Second, RA21 will only be storing user preference information
about which IDP to pass credentials – NOT the credentials
themselves
– Finally, if they wanted, publishers could use other methods to
track user behavior, but are often limited by contracts and laws.
Google CASA Project
(Campus Activated Subscriber Access)
• Outside of the scope or RA21, but attempting to address
similar questions
• Led by Google Scholar team with several publisher
vendor partners
• Based on Google user-behavior analysis and cloud data
to navigate user to identity provider
• Core question: If you don’t trust RA21’s privacy
protections, do you trust Google to protect privacy of
patrons more than publishers/IdPs?
Want to get involved?
•Visit: https://www.RA21.org
•Mailing lists:
–P3W community list: https://lists.refeds.org/sympa/subscribe/p3w-
community
–WAYF Cloud community list: TBD
•Everyone: Register your interest in participation by emailing:
Julie Wallace: Julia@RA21.org and
Heather Flanigan: Heather@RA21.org
Questions?
THANK YOU!
Todd Carpenter
@TAC_NISO
tcarpenter@niso.org

More Related Content

What's hot

Technical introduction to website tracking
Technical introduction to website trackingTechnical introduction to website tracking
Technical introduction to website trackingPanagiotis Tzamtzis
 
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...EOSC-hub project
 
BioSharing, an ELIXIR Interoperability Platform resource
BioSharing, an ELIXIR Interoperability Platform resourceBioSharing, an ELIXIR Interoperability Platform resource
BioSharing, an ELIXIR Interoperability Platform resourcePeter McQuilton
 
Overview of standards/stakeholders in life science (RDA Engagement Interest G...
Overview of standards/stakeholders in life science (RDA Engagement Interest G...Overview of standards/stakeholders in life science (RDA Engagement Interest G...
Overview of standards/stakeholders in life science (RDA Engagement Interest G...Susanna-Assunta Sansone
 
Increasing NUS Libraries' Visibility in the Virtual World - Updated
Increasing NUS Libraries' Visibility in the Virtual World - UpdatedIncreasing NUS Libraries' Visibility in the Virtual World - Updated
Increasing NUS Libraries' Visibility in the Virtual World - UpdatedKC Tan
 
Towards full end-users control of social recommendations
Towards full end-users control of social recommendationsTowards full end-users control of social recommendations
Towards full end-users control of social recommendationsGabriela Bosetti
 

What's hot (8)

Technical introduction to website tracking
Technical introduction to website trackingTechnical introduction to website tracking
Technical introduction to website tracking
 
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
 
ALA NISO Access and License Indicators Lagace
ALA NISO Access and License Indicators LagaceALA NISO Access and License Indicators Lagace
ALA NISO Access and License Indicators Lagace
 
BioSharing, an ELIXIR Interoperability Platform resource
BioSharing, an ELIXIR Interoperability Platform resourceBioSharing, an ELIXIR Interoperability Platform resource
BioSharing, an ELIXIR Interoperability Platform resource
 
Overview of standards/stakeholders in life science (RDA Engagement Interest G...
Overview of standards/stakeholders in life science (RDA Engagement Interest G...Overview of standards/stakeholders in life science (RDA Engagement Interest G...
Overview of standards/stakeholders in life science (RDA Engagement Interest G...
 
Increasing NUS Libraries' Visibility in the Virtual World - Updated
Increasing NUS Libraries' Visibility in the Virtual World - UpdatedIncreasing NUS Libraries' Visibility in the Virtual World - Updated
Increasing NUS Libraries' Visibility in the Virtual World - Updated
 
Towards full end-users control of social recommendations
Towards full end-users control of social recommendationsTowards full end-users control of social recommendations
Towards full end-users control of social recommendations
 
Technology Evaluation and Meeting the Needs of People with Disabilities
Technology Evaluation and Meeting the Needs of People with Disabilities Technology Evaluation and Meeting the Needs of People with Disabilities
Technology Evaluation and Meeting the Needs of People with Disabilities
 

Similar to RA21 and Privacy - NISO ALA Annual 2018

OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG: connecting the knowledge community
 
Practical Steps to Address Piracy
Practical Steps to Address PiracyPractical Steps to Address Piracy
Practical Steps to Address PiracyChris Shillum
 
Bringing the Cloud Back to Earth
Bringing the Cloud Back to EarthBringing the Cloud Back to Earth
Bringing the Cloud Back to EarthSri Chalasani
 
ALIGNED Data Curation Methods and Tools
ALIGNED Data Curation Methods and ToolsALIGNED Data Curation Methods and Tools
ALIGNED Data Curation Methods and ToolsAlignedProject
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptxirfanullahkhan64
 
Webinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online contentWebinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online contentOpenAthens
 
Neo4j GraphDay Seattle- Sept19- Connected data imperative
Neo4j GraphDay Seattle- Sept19- Connected data imperativeNeo4j GraphDay Seattle- Sept19- Connected data imperative
Neo4j GraphDay Seattle- Sept19- Connected data imperativeNeo4j
 
The what, why, and how of accessibility
The what, why, and how of accessibilityThe what, why, and how of accessibility
The what, why, and how of accessibility3Play Media
 
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...Blackboard APAC
 
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...Edge AI and Vision Alliance
 
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...Rachel Vacek
 

Similar to RA21 and Privacy - NISO ALA Annual 2018 (20)

Flanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly ResourcesFlanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly Resources
 
RA21: An Update on RA21
RA21: An Update on RA21RA21: An Update on RA21
RA21: An Update on RA21
 
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
 
RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation
 
Practical Steps to Address Piracy
Practical Steps to Address PiracyPractical Steps to Address Piracy
Practical Steps to Address Piracy
 
Carpenter, "RA21 Update"
Carpenter, "RA21 Update"Carpenter, "RA21 Update"
Carpenter, "RA21 Update"
 
NISO April 30th RA21 Webinar
NISO April 30th RA21 WebinarNISO April 30th RA21 Webinar
NISO April 30th RA21 Webinar
 
Chris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentationChris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentation
 
Bringing the Cloud Back to Earth
Bringing the Cloud Back to EarthBringing the Cloud Back to Earth
Bringing the Cloud Back to Earth
 
ALIGNED Data Curation Methods and Tools
ALIGNED Data Curation Methods and ToolsALIGNED Data Curation Methods and Tools
ALIGNED Data Curation Methods and Tools
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptx
 
Hamparian - IP Authentication for STEM e-Content Access
Hamparian - IP Authentication for STEM e-Content AccessHamparian - IP Authentication for STEM e-Content Access
Hamparian - IP Authentication for STEM e-Content Access
 
Webinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online contentWebinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online content
 
Neo4j GraphDay Seattle- Sept19- Connected data imperative
Neo4j GraphDay Seattle- Sept19- Connected data imperativeNeo4j GraphDay Seattle- Sept19- Connected data imperative
Neo4j GraphDay Seattle- Sept19- Connected data imperative
 
The what, why, and how of accessibility
The what, why, and how of accessibilityThe what, why, and how of accessibility
The what, why, and how of accessibility
 
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
 
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...
“Responsible AI: Tools and Frameworks for Developing AI Solutions,” a Present...
 
NISO's Open Discovery Initiative: Improving Transparency surrounding indexed ...
NISO's Open Discovery Initiative: Improving Transparency surrounding indexed ...NISO's Open Discovery Initiative: Improving Transparency surrounding indexed ...
NISO's Open Discovery Initiative: Improving Transparency surrounding indexed ...
 
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...
Hitting the Road towards a Greater Digital Destination: Evaluating and Testin...
 

More from National Information Standards Organization (NISO)

More from National Information Standards Organization (NISO) (20)

Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
 
Ross and Clark "Strategic Planning"
Ross and Clark "Strategic Planning"Ross and Clark "Strategic Planning"
Ross and Clark "Strategic Planning"
 
Mattingly "Data Mining Techniques: Classification and Clustering"
Mattingly "Data Mining Techniques: Classification and Clustering"Mattingly "Data Mining Techniques: Classification and Clustering"
Mattingly "Data Mining Techniques: Classification and Clustering"
 
Straza "Global collaboration towards equitable and open science: UNESCO Recom...
Straza "Global collaboration towards equitable and open science: UNESCO Recom...Straza "Global collaboration towards equitable and open science: UNESCO Recom...
Straza "Global collaboration towards equitable and open science: UNESCO Recom...
 
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
 
Kriegsman "Integrating Open and Equitable Research into Open Science"
Kriegsman "Integrating Open and Equitable Research into Open Science"Kriegsman "Integrating Open and Equitable Research into Open Science"
Kriegsman "Integrating Open and Equitable Research into Open Science"
 
Mattingly "Ethics and Cleaning Data"
Mattingly "Ethics and Cleaning Data"Mattingly "Ethics and Cleaning Data"
Mattingly "Ethics and Cleaning Data"
 
Mercado-Lara "Open & Equitable Program"
Mercado-Lara "Open & Equitable Program"Mercado-Lara "Open & Equitable Program"
Mercado-Lara "Open & Equitable Program"
 

Recently uploaded

Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfAdmir Softic
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13Steve Thomason
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Celine George
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAssociation for Project Management
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfAyushMahapatra5
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)eniolaolutunde
 
General AI for Medical Educators April 2024
General AI for Medical Educators April 2024General AI for Medical Educators April 2024
General AI for Medical Educators April 2024Janet Corral
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDThiyagu K
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhikauryashika82
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxheathfieldcps1
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphThiyagu K
 

Recently uploaded (20)

Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)
 
General AI for Medical Educators April 2024
General AI for Medical Educators April 2024General AI for Medical Educators April 2024
General AI for Medical Educators April 2024
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SD
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 

RA21 and Privacy - NISO ALA Annual 2018

  • 1. Let’s Talk About Privacy and RA21 Todd Carpenter, Executive Director, National Information Standards Organization (NISO) Dan Ayala, CISO & Privacy Officer, ProQuest Andrew Anderson, President, Library and Information Resources Network, Inc. NISO RA21 ALA Annual Conference June 24, 2018
  • 3. Behind the scenes: Does the user have access rights? Yes or No? Do you have a login? Yes or No? Where are you from? ??????
  • 4. An Analogy: Credit card processing Excuse me. To process this payment you need to tell me: What is the payment processing clearinghouse your bank uses?
  • 5. And patrons are just getting annoyed
  • 6.
  • 7. RA21 wants to build on the user experience of the wider web
  • 8. Make the login experience match the user experience we’re all familiar with Private Experience Target Institutional Experience
  • 9. How SAML Can Protect Privacy Publishers receive attributes about the user, not the user’s identity.
  • 10. RA21 Pilots • Corporate Pilot (Universal Resrource Access “URA”) •Two Academic Pilots – Privacy Preserving Persistent WAYF Pilot – WAYF Cloud Pilot All seek to address the User Experience for off-campus access
  • 11. Initial Privacy Review of RA21 Pilots SECURITY & PRIVACY RECOMMENDATIONS Cloud WAYF P3W Privacy Policy Requirements √ √ Data Protection Impact Analysis Required √ √ Data Retention Policy Required √ Denial of Service Protection √ Browser security (https + access controls) implementations √ √ Database/data protection best practices √ Server hardening - for security threats √ √ Code Scanning - for security threats √ √ Vulnerability Scanning/Penetration Testing √ √ API security protocols √ Audit Logging and review √ Security Monitoring √ Incident Response Plan √ High Availability Infrastructure requirements √ √ Anti-virus software monitoring √ √ GDPR compliance concerns √
  • 12. Privacy Preserving Persistent (P3) WAYF Pilot •Pilot goals – To improve current Shibboleth Identity Provider discovery process • Incorporate additional “WAYF hints” such as email domain and IP address into federation metadata • Improve sign-in flow using those WAYF hints via a shared discovery service • Populate shared discovery service hints from the Service Providers regarding what Identity Providers are likely to work in an authorization scenario • Enable cross-provider persistence of WAYF choice using browser local storage •Pilot participants (confirmed so far) Project Management GÉANT Educational Access Management Federations Sunet & SWAMiD (Swedish Federation) The samlbits.org project eduGAIN EduServ Publishers Elsevier American Chemical Society Subscribing institutions MIT University of California, Davis University of Arizona (tbc) University of Denver (tbc) Service Providers ProQuest Ping LibLynx Ebsco
  • 13. Preserving Privacy Built upon ”SAML-BITS” technology in production Technique Challenge Only domain part of email address needs to be transmitted from browser to publisher platform to select IDP Need to define and test a standardized UI that makes this clear to users IdP preference is stored locally in the browser, retrieved using centrally served javascript, not on a central server Need to adapt Account Choose mechanism to support SAML IdPs vs OpenID Connect Authorization Servers
  • 14. It’s Not That Scary: A Short Demo https://www.youtube.com/watch?v=mkQC64zfNyw&feature=youtu.be Prototype demo starts at 1:22:01 in the recording
  • 15. CRITICISM OF RA21 • Yes, SciHub is a motivator of RA21, but not the only motivator. • This project began with outreach from LIBRARIES! • There are a variety of reasons why libraries would like to improve access control • Evil twins? Come on….
  • 16. MORE CRITICISM OF RA21 • Open Access is not the end-all be-all of library access control issues. – First, even if every journal article were OA, not all content provided by libraries will be freely available – Second, a variety of the services that libraries provide will still need authentication, regardless of whether they are free or not – To presume that RA21 is a fight against open access is to have a very narrow and dim view of what libraries do and provide.
  • 17. EVEN MORE CRITICISM OF RA21 • RA21 is a nefarious plot by publishers to hoover up all sorts of patron data. – First, SAML data released by identity federations is under the control of institutions, who can set limits on what data is released or not, it is NOT controlled by publishers – Second, RA21 will only be storing user preference information about which IDP to pass credentials – NOT the credentials themselves – Finally, if they wanted, publishers could use other methods to track user behavior, but are often limited by contracts and laws.
  • 18. Google CASA Project (Campus Activated Subscriber Access) • Outside of the scope or RA21, but attempting to address similar questions • Led by Google Scholar team with several publisher vendor partners • Based on Google user-behavior analysis and cloud data to navigate user to identity provider • Core question: If you don’t trust RA21’s privacy protections, do you trust Google to protect privacy of patrons more than publishers/IdPs?
  • 19.
  • 20. Want to get involved? •Visit: https://www.RA21.org •Mailing lists: –P3W community list: https://lists.refeds.org/sympa/subscribe/p3w- community –WAYF Cloud community list: TBD •Everyone: Register your interest in participation by emailing: Julie Wallace: Julia@RA21.org and Heather Flanigan: Heather@RA21.org

Editor's Notes

  1. So what are the pilots you ask? We have a Corporate Pilot as well as two academic pilots: The P3W pilot - Privacy Preserving Persistent WAYF Pilot - quite the tongue twister And the WAYF Cloud pilot All seek to address the experience of access outside an institute and to streamline the UX – the user experience – in order to have a similar experience throughout – users do not like to be confronted again and again with new interfaces to master. So following this bit of context for an introduction, we can now go into a bit of detail on the pilots themselves.
  2. Two privacy a
  3. So onto the first of the Academic pilots: the Privacy Preserving Persistent (P3) WAYF Pilot. There are several important things we are trying to investigate in this pilot: All pilots are addressing the UX in one way or another – If we don’t streamline the UX for authentication, we won’t get endusers to adopt the solution We want to make sure the identity provider discovery is consistent; we have a multiple of science providers participating – the idea is if an enduser selects your identity with one; they won’t have to repeat for the others; but this sharing of information creates a privacy problem, thus we aim for cross-provider persistence of WAYF choice using browser local storage. There is a rather large set of folks collaborating on this; originally two pilots combined. It is managed by Geant, and has participation of several access management Federations, Sunet, EduServ are two examples, as well as publishers and subscribing institutions MIT UC Davis, and many well known service providers: ProQuest, LibLynx, Ebsco
  4. So to recap – the P3WAYF pilot would like to make clear to users they only require the domain part of their email (some UX challenges there, but we will solve it), and that their IdP preference is stored locally in the browser, retrieved using centrally served javascript, not on central server.
  5. Thank you for your kind attention. We would love to have you involved with any of the pilots. While we currently have a lot of active leadership and participation from the US and UK, we are actively seeking greater involvement from Europe and Australasia. There are a couple of ways you can register your interest: Through our mailing list, or emailing our project leaders directly. We are also happy to answer any questions off line, or connect with me directly Ann Gabriel a.gabriel@Elsevier.com