SlideShare a Scribd company logo
openathens.orgpenathens.org
What can SAML/Shibboleth do for your
institution?
Phil Leahy
Service Relationship Manager
phil.leahy@openathens.net
openathens.orgopenathens.org
Coming up
• The access management toolkit
• What is federated access management?
• Why is a federation involved?
• InCommon, the OpenAthens Federation and more
• Challenges and limitations
• What’s next?
openathens.orgopenathens.org
The access management toolkit
• Vendor-supplied credentials
• Referral URLs
• Peer-to-peer SAML connections
• IP recognition
• Federated access management
openathens.orgopenathens.org
What is federated access management?
• Secure access to digital content and services via single
sign-on
• Authentication federated to the home organisation
• Individual accountability
• Permission- or role-based authorisation
• SAML encrypts and digitally signs all transactions
openathens.orgopenathens.org
How federated access management works
Standard processes to enable access to:
• Desktop or cloud office applications
• Network drives (filestores etc.)
• VLE and/or LMS
• Discovery tools
• Printer
• …and subscribed digital content
openathens.orgopenathens.org
InCommon, the OpenAthens Federation and more
• Academic/research federations nationally
• OpenAthens Federation for everyone else
• Funding is the key
• Benefits
• Common technical framework (with minor policy
differences)
• Wider distribution of implementation costs
openathens.orgopenathens.org
Why is a federation involved?
• SAML is not ‘plug’n’play’ technology
• Technical infrastructure and policy framework
• Integrate once, re-use for multiple products/ services
• Institutions can connect to any participating publisher
• Publishers can connect to any participating Institution
openathens.orgopenathens.org
Department of
Veterans Affairs
Pharma company
Public library
Govt/defence
organisation
Publisher 1
Publisher 2
Publisher 3
Publisher 4
Peer-to-peer SAML
openathens.orgopenathens.org
Department of
Veterans Affairs
Pharma company
Public library
Govt/defence
organisation
Publisher 1
Publisher 2
Publisher 3
Publisher 4
SAML in a federation
OpenAthens
Federation
Tuakiri
(New
Zealand)
AAF
(Australia)
UKFed
openathens.orgopenathens.org
Challenges and limitations
• SAML and Shibboleth are over 15 years old
• Access to IT resources
• Robust identity management processes
• Myths about SAML
• Network security
• Privacy
• Finding a scalable, truly cross-sector solution
openathens.orgopenathens.org
What’s next?
• Will SAML be replaced?
• User-managed access
openathens.orgopenathens.org
What’s next?
“It is time for a major commitment from the scholarly information ecosystem of
libraries, publishers, university IT, and intermediaries… to develop a single user
account for all scholarly e-resources. This account would not only provide
authentication via a researcher’s institutional credentials but also would be the
vehicle through which a variety of additional data-driven services could be provided
on an opt-in basis. The account itself as well as the data it contains would be under
the control of the researcher, and it would therefore travel with the researcher when
changing institutional affiliations.”
Meeting Researchers Where They Start: Roger Schonfeld, March 26, 2015
https://doi.org/10.18665/sr.241038
openathens.orgopenathens.org
What’s next?
• Will SAML be replaced?
• User-managed access
• Continuing interoperability
openathens.orgopenathens.org
Access to Online Resources:
A Guide for the Modern Librarian
https://openathens.org/access-ebook
openathens.orgopenathens.org
Phil Leahy
OpenAthens Service Relationship Manager
phil.leahy@openathens.net
+44 (0) 117 313 8312
Any questions?
openathens.org
docs.openathens.net

More Related Content

What's hot

Pawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
Pawlowski and Beadles: Authentication and Access of Licensed Content in OhioPawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
Pawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
National Information Standards Organization (NISO)
 
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHSOpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens
 
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the userOpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
OpenAthens
 
LLoyd - Web proxy vs. Federated SSO: A Practical Guide
LLoyd - Web proxy vs. Federated SSO: A Practical GuideLLoyd - Web proxy vs. Federated SSO: A Practical Guide
LLoyd - Web proxy vs. Federated SSO: A Practical Guide
National Information Standards Organization (NISO)
 
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
OpenAthens
 
Leahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSOLeahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSO
National Information Standards Organization (NISO)
 
Gary Price: Some Thoughts on Privacy + Resources
Gary Price: Some Thoughts on Privacy + ResourcesGary Price: Some Thoughts on Privacy + Resources
Gary Price: Some Thoughts on Privacy + Resources
gary_price_infoDOCEKT
 
Identity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy LutherIdentity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy Luther
National Information Standards Organization (NISO)
 
OpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital content
OpenAthens
 
Flanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly ResourcesFlanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly Resources
National Information Standards Organization (NISO)
 
Service Providers within the UK Access Management Federation
Service Providers within the UK Access Management FederationService Providers within the UK Access Management Federation
Service Providers within the UK Access Management Federation
JISC.AM
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
OpenAthens
 
Lorcan Dempsey 20080521
Lorcan Dempsey 20080521Lorcan Dempsey 20080521
Lorcan Dempsey 20080521
ent12701
 
Wenger Replacing IP Filtering: Challenges for Academic Libraries
Wenger Replacing IP Filtering: Challenges for Academic LibrariesWenger Replacing IP Filtering: Challenges for Academic Libraries
Wenger Replacing IP Filtering: Challenges for Academic Libraries
National Information Standards Organization (NISO)
 
SAML protected resources: the theory and practice of granularity and manageme...
SAML protected resources: the theory and practice of granularity and manageme...SAML protected resources: the theory and practice of granularity and manageme...
SAML protected resources: the theory and practice of granularity and manageme...
EDINA, University of Edinburgh
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
OpenAthens
 
Access Management for Libraries by John Paschoud & Masha Garibyan
Access Management for Libraries by John Paschoud & Masha GaribyanAccess Management for Libraries by John Paschoud & Masha Garibyan
Access Management for Libraries by John Paschoud & Masha Garibyan
JISC.AM
 
Collective Digital Collaboration In Asia
Collective Digital Collaboration In AsiaCollective Digital Collaboration In Asia
Collective Digital Collaboration In Asia
Joseph Yap
 
Challenges in accessing e resources
Challenges in accessing e resourcesChallenges in accessing e resources
Challenges in accessing e resources
OpenAthens
 
2016 02-04-gingell-iot
2016 02-04-gingell-iot2016 02-04-gingell-iot
2016 02-04-gingell-iot
gingell
 

What's hot (20)

Pawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
Pawlowski and Beadles: Authentication and Access of Licensed Content in OhioPawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
Pawlowski and Beadles: Authentication and Access of Licensed Content in Ohio
 
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHSOpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
OpenAthens Conference 2018 - Catherine Micklethwaite - Case study - NHS
 
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the userOpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
 
LLoyd - Web proxy vs. Federated SSO: A Practical Guide
LLoyd - Web proxy vs. Federated SSO: A Practical GuideLLoyd - Web proxy vs. Federated SSO: A Practical Guide
LLoyd - Web proxy vs. Federated SSO: A Practical Guide
 
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
OpenAthens Conference 2018 - Tim Lull and Chad Smith - Cultivating your onlin...
 
Leahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSOLeahy Transforming the User Experience with Identity Management and SSO
Leahy Transforming the User Experience with Identity Management and SSO
 
Gary Price: Some Thoughts on Privacy + Resources
Gary Price: Some Thoughts on Privacy + ResourcesGary Price: Some Thoughts on Privacy + Resources
Gary Price: Some Thoughts on Privacy + Resources
 
Identity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy LutherIdentity & Authentication Management - Judy Luther
Identity & Authentication Management - Judy Luther
 
OpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital contentOpenAthens Cloud - Global access to your digital content
OpenAthens Cloud - Global access to your digital content
 
Flanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly ResourcesFlanagan - RA21 Improving Access to Scholarly Resources
Flanagan - RA21 Improving Access to Scholarly Resources
 
Service Providers within the UK Access Management Federation
Service Providers within the UK Access Management FederationService Providers within the UK Access Management Federation
Service Providers within the UK Access Management Federation
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
 
Lorcan Dempsey 20080521
Lorcan Dempsey 20080521Lorcan Dempsey 20080521
Lorcan Dempsey 20080521
 
Wenger Replacing IP Filtering: Challenges for Academic Libraries
Wenger Replacing IP Filtering: Challenges for Academic LibrariesWenger Replacing IP Filtering: Challenges for Academic Libraries
Wenger Replacing IP Filtering: Challenges for Academic Libraries
 
SAML protected resources: the theory and practice of granularity and manageme...
SAML protected resources: the theory and practice of granularity and manageme...SAML protected resources: the theory and practice of granularity and manageme...
SAML protected resources: the theory and practice of granularity and manageme...
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
 
Access Management for Libraries by John Paschoud & Masha Garibyan
Access Management for Libraries by John Paschoud & Masha GaribyanAccess Management for Libraries by John Paschoud & Masha Garibyan
Access Management for Libraries by John Paschoud & Masha Garibyan
 
Collective Digital Collaboration In Asia
Collective Digital Collaboration In AsiaCollective Digital Collaboration In Asia
Collective Digital Collaboration In Asia
 
Challenges in accessing e resources
Challenges in accessing e resourcesChallenges in accessing e resources
Challenges in accessing e resources
 
2016 02-04-gingell-iot
2016 02-04-gingell-iot2016 02-04-gingell-iot
2016 02-04-gingell-iot
 

Similar to What can SAML / Shibboleth do for your institution?

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
Eduserv
 
Introducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providersIntroducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providers
OpenAthens
 
What is federated single sign-on?
What is federated single sign-on?What is federated single sign-on?
What is federated single sign-on?
OpenAthens
 
Quick wins for an easier user journey
Quick wins for an easier user journeyQuick wins for an easier user journey
Quick wins for an easier user journey
OpenAthens
 
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
TechSoup
 
COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)
CASRAI
 
Sept 24 NISO Virtual Conference: Library Data in the Cloud
Sept 24 NISO Virtual Conference: Library Data in the CloudSept 24 NISO Virtual Conference: Library Data in the Cloud
Sept 24 NISO Virtual Conference: Library Data in the Cloud
National Information Standards Organization (NISO)
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledge
OpenAthens
 
AALL Webinar: Technology Tools for Law Librarians
AALL Webinar:  Technology Tools for Law LibrariansAALL Webinar:  Technology Tools for Law Librarians
AALL Webinar: Technology Tools for Law Librarians
Lisa Smith-Butler
 
SHARE Notification Service, December 2014
SHARE Notification Service, December 2014SHARE Notification Service, December 2014
SHARE Notification Service, December 2014
SHARE
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG: connecting the knowledge community
 
GALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnershipGALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnership
OpenAthens
 
Trends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the RisksTrends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the Risks
Nicole Garton
 
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
Cheryl McKinnon
 
OpenAthens Service Provider in the cloud: development update
OpenAthens Service Provider in the cloud: development update OpenAthens Service Provider in the cloud: development update
OpenAthens Service Provider in the cloud: development update
Eduserv
 
OA in the Library Collection: The Challenge of Identifying and Managing Open ...
OA in the Library Collection: The Challenge of Identifying and Managing Open ...OA in the Library Collection: The Challenge of Identifying and Managing Open ...
OA in the Library Collection: The Challenge of Identifying and Managing Open ...
NASIG
 
Iam it-summit-2015
Iam it-summit-2015Iam it-summit-2015
Iam it-summit-2015
kevin_donovan
 
Some Thoughts on Libraries, Ethics, and Privacy
Some Thoughts on Libraries, Ethics, and PrivacySome Thoughts on Libraries, Ethics, and Privacy
Some Thoughts on Libraries, Ethics, and Privacy
GaryPrice_infoDOCKET
 
Webinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online contentWebinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online content
OpenAthens
 
D2L Brightspace Vendor Integrations: Technology and Terminology
D2L Brightspace Vendor Integrations: Technology and TerminologyD2L Brightspace Vendor Integrations: Technology and Terminology
D2L Brightspace Vendor Integrations: Technology and Terminology
D2L Barry
 

Similar to What can SAML / Shibboleth do for your institution? (20)

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
 
Introducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providersIntroducing OpenAthens Cloud for content providers
Introducing OpenAthens Cloud for content providers
 
What is federated single sign-on?
What is federated single sign-on?What is federated single sign-on?
What is federated single sign-on?
 
Quick wins for an easier user journey
Quick wins for an easier user journeyQuick wins for an easier user journey
Quick wins for an easier user journey
 
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
 
COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)COAR: All About the SHared Access Research Ecosystem (SHARE)
COAR: All About the SHared Access Research Ecosystem (SHARE)
 
Sept 24 NISO Virtual Conference: Library Data in the Cloud
Sept 24 NISO Virtual Conference: Library Data in the CloudSept 24 NISO Virtual Conference: Library Data in the Cloud
Sept 24 NISO Virtual Conference: Library Data in the Cloud
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledge
 
AALL Webinar: Technology Tools for Law Librarians
AALL Webinar:  Technology Tools for Law LibrariansAALL Webinar:  Technology Tools for Law Librarians
AALL Webinar: Technology Tools for Law Librarians
 
SHARE Notification Service, December 2014
SHARE Notification Service, December 2014SHARE Notification Service, December 2014
SHARE Notification Service, December 2014
 
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
 
GALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnershipGALILEO virtual library and OpenAthens partnership
GALILEO virtual library and OpenAthens partnership
 
Trends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the RisksTrends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the Risks
 
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...What Do Records Managers Need to Know About Open Source, Open Standards, Open...
What Do Records Managers Need to Know About Open Source, Open Standards, Open...
 
OpenAthens Service Provider in the cloud: development update
OpenAthens Service Provider in the cloud: development update OpenAthens Service Provider in the cloud: development update
OpenAthens Service Provider in the cloud: development update
 
OA in the Library Collection: The Challenge of Identifying and Managing Open ...
OA in the Library Collection: The Challenge of Identifying and Managing Open ...OA in the Library Collection: The Challenge of Identifying and Managing Open ...
OA in the Library Collection: The Challenge of Identifying and Managing Open ...
 
Iam it-summit-2015
Iam it-summit-2015Iam it-summit-2015
Iam it-summit-2015
 
Some Thoughts on Libraries, Ethics, and Privacy
Some Thoughts on Libraries, Ethics, and PrivacySome Thoughts on Libraries, Ethics, and Privacy
Some Thoughts on Libraries, Ethics, and Privacy
 
Webinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online contentWebinar: Preserving user privacy and protecting online content
Webinar: Preserving user privacy and protecting online content
 
D2L Brightspace Vendor Integrations: Technology and Terminology
D2L Brightspace Vendor Integrations: Technology and TerminologyD2L Brightspace Vendor Integrations: Technology and Terminology
D2L Brightspace Vendor Integrations: Technology and Terminology
 

More from OpenAthens

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptx
OpenAthens
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledge
OpenAthens
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
OpenAthens
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccess
OpenAthens
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmap
OpenAthens
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementation
OpenAthens
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthens
OpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...
OpenAthens
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital products
OpenAthens
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users too
OpenAthens
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
OpenAthens
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation?
OpenAthens
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhere
OpenAthens
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charter
OpenAthens
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge services
OpenAthens
 
Access lab 2020: The Future of Libraries
Access lab 2020: The Future of LibrariesAccess lab 2020: The Future of Libraries
Access lab 2020: The Future of Libraries
OpenAthens
 
Missing link in the publishing cycle - 12 February 2020
Missing link in the publishing cycle  - 12 February 2020Missing link in the publishing cycle  - 12 February 2020
Missing link in the publishing cycle - 12 February 2020
OpenAthens
 
Librarian's experiences
Librarian's experiences Librarian's experiences
Librarian's experiences
OpenAthens
 
UX recommendations for publishers
UX recommendations for publishersUX recommendations for publishers
UX recommendations for publishers
OpenAthens
 
OpenAthens Conference 2019: Three models for UX design
OpenAthens Conference 2019: Three models for UX design OpenAthens Conference 2019: Three models for UX design
OpenAthens Conference 2019: Three models for UX design
OpenAthens
 

More from OpenAthens (20)

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptx
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledge
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccess
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmap
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementation
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital products
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users too
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation?
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhere
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charter
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge services
 
Access lab 2020: The Future of Libraries
Access lab 2020: The Future of LibrariesAccess lab 2020: The Future of Libraries
Access lab 2020: The Future of Libraries
 
Missing link in the publishing cycle - 12 February 2020
Missing link in the publishing cycle  - 12 February 2020Missing link in the publishing cycle  - 12 February 2020
Missing link in the publishing cycle - 12 February 2020
 
Librarian's experiences
Librarian's experiences Librarian's experiences
Librarian's experiences
 
UX recommendations for publishers
UX recommendations for publishersUX recommendations for publishers
UX recommendations for publishers
 
OpenAthens Conference 2019: Three models for UX design
OpenAthens Conference 2019: Three models for UX design OpenAthens Conference 2019: Three models for UX design
OpenAthens Conference 2019: Three models for UX design
 

Recently uploaded

Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
DianaGray10
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
DianaGray10
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Product School
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
Abida Shariff
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
Ralf Eggert
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
Elena Simperl
 

Recently uploaded (20)

Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 

What can SAML / Shibboleth do for your institution?

Editor's Notes

  1. Security through obscurity: “Security experts have rejected this view as far back as 1851” https://en.wikipedia.org/wiki/Security_through_obscurity Institutional U/Ps have been shared as long as they have been available – SciHub is only the latest evidence of that.
  2. Users automatically onboarded when their network account is created Consistent, personalised user experience, creating more opportunities to discover, access and engage with content. Easier to comply with restricted content licences A users home organisation verifies their identity at log in and passes encrypted attribute data to the service provider who then authorises access to their content. As the limits of IP recognition are increasingly exposed from both a usability and security point of view, so more secure standards such as SAML-based SSO are emerging as the best way to ensure services are protected against misuse. SAML brings a number of benefits. It allows organisations to send information to content providers securely. By default, SAML digitally signs and encrypts all data sent in each direction. This helps to: prevent fraudulent use or interception keep all user information private, including their login details SAML also gives organisations granular control over what attributes are exchanged with particular resources. So an organisation could pass a forename, surname and email to one publisher, but restrict all the others to seeing only their job role, or subject specialisation. And of course that means it enables personalisation. Without personalisation, none of the benefits of a modern digital service are available, i.e. more engagement, attracting users to return, learning more about their needs and tailoring products accordingly. That level of detail helps everyone. It helps content providers segment their products and direct it at particular users, and by providing greater transparency of how collections are being used, it helps an organisation make more informed purchase decisions. And in these days of greater compliance requirements, SAML helps content providers and their customers conform to best practices which meet contractual expectations around securing access to information resources. But most importantly, it provides a superior end-user experience regardless of whether they are accessing resources from within an institution’s network or on the go.
  3. Here’s a typical scenario: when a new user enrols at a university or starts work at a new job, that organisation will have a process which automatically grants access to the internal and external resources they need to participate in their course or do their job. That process applies the appropriate permissions and controls to ensure they can only access what they entitled to and will typically include access to their nearest printer, the network drives for access to the documents they need and increasingly, their organisation’s subscription content – all with a single username and password.
  4. Your institutions' licence fees pay for everything a publisher uses, from paper clips to cleaning services to access management solutions. If driving users from multiple customers to a single access point is cheaper for service providers, it ought to be cheaper for institutions The InCommon Federation is the U.S. education and research identity federation, providing a common framework for trusted shared management of access to online resources.
  5. SAML 2.0 offers many different options on passing attributes, how to use PKI (certificates) and other implementation details Most access management federations have broadly similar policies Implementation differences are usually minor but each has to be coded for
  6. So here is what we often see of how SAML is deployed between content providers and their customers. When a subscription is put in place, a content provider might say “we can connect via SAML if you like”. [Publisher speaks to Customer One] [Publisher speaks to Customer Two] [and so on and so on] [Customer One speaks to Publisher Two] What you end up with is a series of parallel, single-use connections which can’t be re-used and which have to be individually managed. This is not an efficient model. But every single one of those conversations requires a developer, not just for the publisher's platform but at the customer end too. If the organisation has limited technical resources, which is often the case with SAML, that task will be outside their technical comfort zone and they can struggle to complete the integration. That makes it both a difficult and expensive option for everyone. It’s already expensive for publishers simply because a developer is involved.  But even then, using SAML doesn’t guarantee a consistent and repeatable setup. I was copied into an email conversation between a content provider and their customer where over the course of a couple of weeks, five different user ID formats were considered for use in the SAML transaction. Then I saw quotes such as: “it doesn’t look like the NameID matches what we have on file” “The difference was SAML ACS URL wasn’t capitalized. They have to match exactly” After all of that, the user IDs had to be uploaded into the content provider’s platform before anyone could use it. So onboarding new users requires additional technical tasks. I would ask two questions of those publishers: Why are you asking your customers to perform technical setups for which the majority won’t have the expertise? Shouldn’t you be allowing your developers to support and develop your core business, rather using than a technology with its own management overhead?
  7. Let me be clear: this is federated access management, because authentication is federated to the subscribing organisation and they manage their own user records. However, as I previously said it is a series of parallel, single-use connections which can’t be re-used and have to be individually managed. That is not efficient. But could a content provider's developers complete an integration task once, and then re-use that multiple times? The answer to that is: Yes. The OpenAthens Federation allows content providers to integrate once, and re-use this for multiple customers.
  8. SAML is heavyweight technology Ongoing maintenance required Specialist knowledge is in short supply OIDC already seen as an alternative by some Hospitals tend to have extremely locked down IT environments, some hospitals more than others…The hospital IT department does not care about the library. Hospitals already hooking their ADFS identity management layer into OAFed. Federated access management works best when everything is hooked in but org-wide IDM strategy can be intimidating
  9. OIDC or other emerging web services/APIs Roger Schonfeld and others have been advocating this for some time – but the privacy issues remain Concept of interoperability now well-established
  10. OIDC or other emerging web services/APIs Roger Schonfeld and others have been advocating this for some time – but the privacy issues remain Concept of interoperability now well-established
  11. Free ebook! Written by Kristina Botyriute, OpenAthens Lead Technical Pre-Sales Consultant, to help information professionals confidently address authentication issues and challenges. The difference between authentication and authorisation Web based authentication IP address recognition What SAML is and how it works OpenID Connect Basic troubleshooting