SlideShare a Scribd company logo
Back to Basics: What is
federated single sign-on?
25 January 2023
Christos Skoutas, senior business development manager, OpenAthens
2
Housekeeping
1. We are recording
2. Post speaker
questions in the Q&A
3. Post general
queries in the chat
4. Live transcript
is on
Back to Basics: What is
federated single sign-on?
25 January 2023
Christos Skoutas, senior business development manager, OpenAthens
4
What we’ll cover
• Introduction
• What technologies are used in the
library/publishing space?
• What is federated single sign-on
technology?
• What are the benefits of this type of
technology for users/libraries/publishers
• Questions
5
Authentication technologies
What’s happened in the last 25 years?
6
What is IP
recognition?
Photo by Clay Banks on Unsplash
7
Proxy services
Photo by Devon Divine on Unsplash
• IP access outside the
campus is not available
• Proxy services deal with
off-campus access dilemma
• IP address is passed to the
publishers
8
Covid-19 accelerated remote access to resources
Institutions update their
digital infrastructure to offer
remote learning to their
patrons
Emphasis on
technology to
maximize online and
hybrid learning
Remote access to
library resources
increased massively
9
The problem with IP recognition
Photo by JESHOOTS.COM on Unsplash
• Authentication and
authorization
• User experience
• Maintenance
• Security
10
Increased security risks during Covid-19
pandemic
https://www.theguardian.com/world/2020/nov/22/hackers-try-to-steal-covid-vaccine-secrets-in-intellectual-property-war
https://www.fiercepharma.com/pharma/not-just-astrazeneca-north-korean-hackers-targeted-5-other-covid-drug-developers-wsj
“In recent months, we’ve detected cyberattacks
from three nation-state actors targeting seven
prominent companies directly involved in
researching vaccines and treatments for Covid-19.”
Tom Burt, Corporate Vice President, Customer
Security & Trust, Microsoft
Not just AstraZeneca: Hackers
targeted 5 other COVID-19 drug
developers, vaccine cold chain
suppliers
Wall Street Journal
Academic institutions are not
well-resourced and defended,
and researchers have to be
educated about the risks
The Guardian
Hackers ‘try to steal
Covid vaccine secrets in
intellectual property war’
The Guardian
11
Proxy services: a threat to researchers and
organizations
• Sci-Hub and other bad
actors exploit the sentiment
around open access to
research articles
• >90% of compromise is
through proxy services
Source: Elsevier data: April 2019-June 2020 https://www.youtube.com/watch?v=KqVo2Pj06dE
12
What is federated
authentication and
single sign-on?
13
User journey without single sign-on
Password 1
Password 1
Password 1
Password 1
Password 1
Resource 1
Resource 2
Resource 3
Resource 4
Resource 5
14
User journey with single sign-on
Password 1
Resource 1
Resource 2
Resource 3
Resource 4
Resource 5
15
How federated single sign-on works
I want to
access an
article
Organization, do you know Jane?
Hi resource, yes Jane is a student here
16
The concept of federated identity
management
• More secure
• Data encryption is standard
• Individual accountability
17
Identity federations
• Shared trust network
• Standards based (SAML
protocol)
• Centrally managed
18
What are the key benefits?
• Better user experience
• More secure
• Cost efficient
19
Better user
experience
20
User journey patterns
“Users have kind of pattern…they start in Google to get an idea of the keywords they will need and
the scale of the queries they may want to do and then, they go to more refine resources like
discovery tools, library catalogues, google scholar or specific disciplines databases”
Caroline Gauld, University of Melbourne (https://www.youtube.com/watch?v=SXCi515julE)
“People discover articles through search around 45% of the time. 55% of the time they are doing
something else. However, discovery via search has increased over time”
How Readers Discover Content in Scholarly Publications 2021, Gardner, T & al, Renew
Consultants
“Discovery is not as simple as ‘novice’ vs. ‘expert’(…) A professor in one discipline may, for
example, use Wikipedia or basic Google searches to familiarize themselves with a new topic just as
a new student might”
Resource Discovery@ The University of Oxford, Madsen, C & al, Athenaeum21 Consulting
Research
21
Federated single sign-on offers better user
experience
22
Federated single sign-on offers better user
experience
23
Federated single sign-on offers better user
experience
24
Cost efficient
25
26
27
More secure
28
Benefits for
publishers
29
Take aways from today
• Future-proof your
authentication systems
• Secure, resilient and
scalable solution in the
cloud
• Improves user experience
• Saves you time and money
30
Any questions?
31
Thank you
Christos Skoutas
Christos.Skoutas@openathens.net

More Related Content

Similar to What is federated single sign-on?

Open ILRI
Open ILRIOpen ILRI
Open ILRI
ILRI
 
Iam it-summit-2015
Iam it-summit-2015Iam it-summit-2015
Iam it-summit-2015
kevin_donovan
 
The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?
National Information Standards Organization (NISO)
 
Use of PLEs by security and investigation professionals
Use of PLEs by security and investigation professionalsUse of PLEs by security and investigation professionals
Use of PLEs by security and investigation professionals
Tony Ratcliffe
 
How you and your gateway can benefit from the services of the Science Gateway...
How you and your gateway can benefit from the services of the Science Gateway...How you and your gateway can benefit from the services of the Science Gateway...
How you and your gateway can benefit from the services of the Science Gateway...
Katherine Lawrence
 
Panel presentation at ECDL 2009
Panel presentation at ECDL 2009Panel presentation at ECDL 2009
Panel presentation at ECDL 2009Paul Walk
 
Lecture4 Social Web
Lecture4 Social Web Lecture4 Social Web
Lecture4 Social Web
Marieke van Erp
 
SGCI-URSSI-Sustainability in Research Computing
SGCI-URSSI-Sustainability in Research ComputingSGCI-URSSI-Sustainability in Research Computing
SGCI-URSSI-Sustainability in Research Computing
Sandra Gesing
 
Information Architecture Workshop
Information Architecture WorkshopInformation Architecture Workshop
Information Architecture Workshop
Peter Morville
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
OpenAthens
 
Chris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentationChris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentation
National Information Standards Organization (NISO)
 
Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18
Nancy Wilkins-Diehr
 
Webscale Discovery and Information Literacy
Webscale Discovery and Information LiteracyWebscale Discovery and Information Literacy
Webscale Discovery and Information LiteracyCharleston Conference
 
Webscale discovery and information literacy
Webscale discovery and information literacyWebscale discovery and information literacy
Webscale discovery and information literacy
li1smc
 
SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19
Nancy Wilkins-Diehr
 
Health information professionals and Artificial Intelligence
Health information professionals and Artificial IntelligenceHealth information professionals and Artificial Intelligence
Health information professionals and Artificial Intelligence
coxamcoxam
 
“From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
 “From Discovery to Fulfillment: Improving the User Experience at Every Stage.” “From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
“From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
Lynn Connaway
 
Csu library deans june 2014
Csu library deans june 2014Csu library deans june 2014
Csu library deans june 2014Stephen Abram
 
Alamw15 VIVO
Alamw15 VIVOAlamw15 VIVO
Alamw15 VIVO
Kristi Holmes
 
ArcGIS Open Data: Engagement
ArcGIS Open Data: Engagement ArcGIS Open Data: Engagement
ArcGIS Open Data: Engagement
sidewalkballet
 

Similar to What is federated single sign-on? (20)

Open ILRI
Open ILRIOpen ILRI
Open ILRI
 
Iam it-summit-2015
Iam it-summit-2015Iam it-summit-2015
Iam it-summit-2015
 
The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?The Future of Research Communications and e-Scholarship: Are we there yet?
The Future of Research Communications and e-Scholarship: Are we there yet?
 
Use of PLEs by security and investigation professionals
Use of PLEs by security and investigation professionalsUse of PLEs by security and investigation professionals
Use of PLEs by security and investigation professionals
 
How you and your gateway can benefit from the services of the Science Gateway...
How you and your gateway can benefit from the services of the Science Gateway...How you and your gateway can benefit from the services of the Science Gateway...
How you and your gateway can benefit from the services of the Science Gateway...
 
Panel presentation at ECDL 2009
Panel presentation at ECDL 2009Panel presentation at ECDL 2009
Panel presentation at ECDL 2009
 
Lecture4 Social Web
Lecture4 Social Web Lecture4 Social Web
Lecture4 Social Web
 
SGCI-URSSI-Sustainability in Research Computing
SGCI-URSSI-Sustainability in Research ComputingSGCI-URSSI-Sustainability in Research Computing
SGCI-URSSI-Sustainability in Research Computing
 
Information Architecture Workshop
Information Architecture WorkshopInformation Architecture Workshop
Information Architecture Workshop
 
Are you giving your users the best online experience - Webinar
Are you giving your users the best online experience - WebinarAre you giving your users the best online experience - Webinar
Are you giving your users the best online experience - Webinar
 
Chris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentationChris Shillum: Overview of the RA21 proejct presentation
Chris Shillum: Overview of the RA21 proejct presentation
 
Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18
 
Webscale Discovery and Information Literacy
Webscale Discovery and Information LiteracyWebscale Discovery and Information Literacy
Webscale Discovery and Information Literacy
 
Webscale discovery and information literacy
Webscale discovery and information literacyWebscale discovery and information literacy
Webscale discovery and information literacy
 
SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19
 
Health information professionals and Artificial Intelligence
Health information professionals and Artificial IntelligenceHealth information professionals and Artificial Intelligence
Health information professionals and Artificial Intelligence
 
“From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
 “From Discovery to Fulfillment: Improving the User Experience at Every Stage.” “From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
“From Discovery to Fulfillment: Improving the User Experience at Every Stage.”
 
Csu library deans june 2014
Csu library deans june 2014Csu library deans june 2014
Csu library deans june 2014
 
Alamw15 VIVO
Alamw15 VIVOAlamw15 VIVO
Alamw15 VIVO
 
ArcGIS Open Data: Engagement
ArcGIS Open Data: Engagement ArcGIS Open Data: Engagement
ArcGIS Open Data: Engagement
 

More from OpenAthens

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptx
OpenAthens
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledge
OpenAthens
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
OpenAthens
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
OpenAthens
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccess
OpenAthens
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledge
OpenAthens
 
Access Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integrationAccess Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integration
OpenAthens
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmap
OpenAthens
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementation
OpenAthens
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthens
OpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...
OpenAthens
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital products
OpenAthens
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users too
OpenAthens
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
OpenAthens
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation?
OpenAthens
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhere
OpenAthens
 
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
OpenAthens
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charter
OpenAthens
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge services
OpenAthens
 
Access lab 2020: The Future of Libraries
Access lab 2020: The Future of LibrariesAccess lab 2020: The Future of Libraries
Access lab 2020: The Future of Libraries
OpenAthens
 

More from OpenAthens (20)

Webinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptxWebinar - Making the business case - resources.pptx
Webinar - Making the business case - resources.pptx
 
Library user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledgeLibrary user experience report: Removing barriers in the search for knowledge
Library user experience report: Removing barriers in the search for knowledge
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
 
IOP Publishing - How we simplified user access
IOP Publishing - How we simplified user accessIOP Publishing - How we simplified user access
IOP Publishing - How we simplified user access
 
Introduction to SeamlessAccess
Introduction to SeamlessAccessIntroduction to SeamlessAccess
Introduction to SeamlessAccess
 
APAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledgeAPAN50 - Removing barriers to knowledge
APAN50 - Removing barriers to knowledge
 
Access Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integrationAccess Lab 2020: FOLIO + OpenAthens integration
Access Lab 2020: FOLIO + OpenAthens integration
 
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmapAccess Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens product roadmap
 
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementationAccess Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: OpenAthens and Alma implementation
 
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthensAccess Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Switching from EzProxy to OpenAthens
 
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: Helping users get on the right path even if they start off o...
 
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital productsAccess Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: From raw content assets to personalised, digital products
 
Access Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users tooAccess Lab 2020: Librarians are users too
Access Lab 2020: Librarians are users too
 
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
 
Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation? Access Lab 2020: Change of identity, loss of personalisation?
Access Lab 2020: Change of identity, loss of personalisation?
 
Access Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhereAccess Lab 2020: Easier access to content from anywhere
Access Lab 2020: Easier access to content from anywhere
 
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...Access Lab 2020: What OpenAthens can do for you: creative applications for th...
Access Lab 2020: What OpenAthens can do for you: creative applications for th...
 
Access Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charterAccess Lab 2020: OpenAthens service availability and customer charter
Access Lab 2020: OpenAthens service availability and customer charter
 
Access Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge servicesAccess Lab 2020: Context aware unified institutional knowledge services
Access Lab 2020: Context aware unified institutional knowledge services
 
Access lab 2020: The Future of Libraries
Access lab 2020: The Future of LibrariesAccess lab 2020: The Future of Libraries
Access lab 2020: The Future of Libraries
 

Recently uploaded

Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
Fwdays
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Tobias Schneck
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
Elena Simperl
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
Elena Simperl
 

Recently uploaded (20)

Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 

What is federated single sign-on?

  • 1. Back to Basics: What is federated single sign-on? 25 January 2023 Christos Skoutas, senior business development manager, OpenAthens
  • 2. 2 Housekeeping 1. We are recording 2. Post speaker questions in the Q&A 3. Post general queries in the chat 4. Live transcript is on
  • 3. Back to Basics: What is federated single sign-on? 25 January 2023 Christos Skoutas, senior business development manager, OpenAthens
  • 4. 4 What we’ll cover • Introduction • What technologies are used in the library/publishing space? • What is federated single sign-on technology? • What are the benefits of this type of technology for users/libraries/publishers • Questions
  • 6. 6 What is IP recognition? Photo by Clay Banks on Unsplash
  • 7. 7 Proxy services Photo by Devon Divine on Unsplash • IP access outside the campus is not available • Proxy services deal with off-campus access dilemma • IP address is passed to the publishers
  • 8. 8 Covid-19 accelerated remote access to resources Institutions update their digital infrastructure to offer remote learning to their patrons Emphasis on technology to maximize online and hybrid learning Remote access to library resources increased massively
  • 9. 9 The problem with IP recognition Photo by JESHOOTS.COM on Unsplash • Authentication and authorization • User experience • Maintenance • Security
  • 10. 10 Increased security risks during Covid-19 pandemic https://www.theguardian.com/world/2020/nov/22/hackers-try-to-steal-covid-vaccine-secrets-in-intellectual-property-war https://www.fiercepharma.com/pharma/not-just-astrazeneca-north-korean-hackers-targeted-5-other-covid-drug-developers-wsj “In recent months, we’ve detected cyberattacks from three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19.” Tom Burt, Corporate Vice President, Customer Security & Trust, Microsoft Not just AstraZeneca: Hackers targeted 5 other COVID-19 drug developers, vaccine cold chain suppliers Wall Street Journal Academic institutions are not well-resourced and defended, and researchers have to be educated about the risks The Guardian Hackers ‘try to steal Covid vaccine secrets in intellectual property war’ The Guardian
  • 11. 11 Proxy services: a threat to researchers and organizations • Sci-Hub and other bad actors exploit the sentiment around open access to research articles • >90% of compromise is through proxy services Source: Elsevier data: April 2019-June 2020 https://www.youtube.com/watch?v=KqVo2Pj06dE
  • 12. 12 What is federated authentication and single sign-on?
  • 13. 13 User journey without single sign-on Password 1 Password 1 Password 1 Password 1 Password 1 Resource 1 Resource 2 Resource 3 Resource 4 Resource 5
  • 14. 14 User journey with single sign-on Password 1 Resource 1 Resource 2 Resource 3 Resource 4 Resource 5
  • 15. 15 How federated single sign-on works I want to access an article Organization, do you know Jane? Hi resource, yes Jane is a student here
  • 16. 16 The concept of federated identity management • More secure • Data encryption is standard • Individual accountability
  • 17. 17 Identity federations • Shared trust network • Standards based (SAML protocol) • Centrally managed
  • 18. 18 What are the key benefits? • Better user experience • More secure • Cost efficient
  • 20. 20 User journey patterns “Users have kind of pattern…they start in Google to get an idea of the keywords they will need and the scale of the queries they may want to do and then, they go to more refine resources like discovery tools, library catalogues, google scholar or specific disciplines databases” Caroline Gauld, University of Melbourne (https://www.youtube.com/watch?v=SXCi515julE) “People discover articles through search around 45% of the time. 55% of the time they are doing something else. However, discovery via search has increased over time” How Readers Discover Content in Scholarly Publications 2021, Gardner, T & al, Renew Consultants “Discovery is not as simple as ‘novice’ vs. ‘expert’(…) A professor in one discipline may, for example, use Wikipedia or basic Google searches to familiarize themselves with a new topic just as a new student might” Resource Discovery@ The University of Oxford, Madsen, C & al, Athenaeum21 Consulting Research
  • 21. 21 Federated single sign-on offers better user experience
  • 22. 22 Federated single sign-on offers better user experience
  • 23. 23 Federated single sign-on offers better user experience
  • 25. 25
  • 26. 26
  • 29. 29 Take aways from today • Future-proof your authentication systems • Secure, resilient and scalable solution in the cloud • Improves user experience • Saves you time and money
  • 31. 31

Editor's Notes

  1. Thank you Jane. Hello everybody and welcome to our webinar. Here is what I would like to cover today. For the people who don’t know me my name is Christos Skoutas and I have been working for OpenAthens for a few years now. I would like to start the presentation with the main ways users have been accessing e-resources the last few years. Then, I will dive into what federated Single Sign-on is, how it came about, why it is important, and what benefits it brings to libraries, publishers, and users. At the end we will have some time for questions and further discussion.
  2. Now, let’s start with what technologies users have been using to access content? When we say users, we mean students/researchers/professors, anybody who needs access to subscribed content online. What we mean by subscribed content is electronic journals/e-databases/ebooks, etc. IP (Internet protocol) recognition is the most widely used technology and it goes back to 1974 as we can see here. Then in the 90s we had other technologies like VPNs, Athens (as we were called back then) and EZproxy. In 2002 a protocol called SAML (SAML stands for Security Assertion Mark-up Language) was introduced, and more recently other protocls like OpenID Connect came about.
  3. IP recognition is an access method that was developed in the early 90s when almost all computers were located in the library. Back then we didn’t have any smartphones and very few people worked or studied remotely. IP addresses back then were static.
  4. When technology advanced and mobile devices like laptops/tablets/mobile phones came about, access outside the campus wasn’t available. That’s when proxy services came in to solve that problem. What IP Proxy services do is that they allow end users to appear to a publisher/content provider as if they were within the physical IP range of the subscribing institution despite the fact they were off campus. Many IP addresses are dynamic and constantly changing over time. The increased use of laptops/smartphones/tablets made the IP recognition model unable to accommodate remote users. To solve this problem institutions started using proxy servers and VPNs. Proxy servers and VPNs aggregate individual user sessions behind a single institutional IP address. Since this address is within the range registered with the publisher, the aggregated connections are accepted.
  5. Now, on top of the technological changes that happened the last 25 years, Covid accelerated this trend and highlighted the need for reliable systems to allow an increased number of remote users to access library resources. During the last 3 years, offering uninterrupted and secure access to e-resources to users based anywhere has become paramount.
  6. Authentication and authorization. These words, authentication and authorisation can be tricky. Authentication is when someone asks the question tell me who you are. You need to prove your affiliation with the organisation. Then, the publisher will make an authorisation decision based on the information that is sent from the institution to the content provider. Authorisation answers the question what you can access. The IP recognition model is constructed on the assumption that an IP address reliably indicates a user’s physical location. This was true back in the 90s but it isn’t now. The model assumes a physical location can be relied on to identify a legitimate authorised user. That means the model conflates IP addresses with location and identity. This is the reason I refer to this model as IP recognition and not IP authentication. The system works by recognising an IP address, not by authenticating an individual user. Regarding User experience. IP recognition requires services like proxy servers or VPNs which require remote users to login to a library portal first, then navigate to online content. This is not a good experience since users cannot access content directly on publishers’ websites. Maintenance. IP recognition is not easy to maintain. If the subscribing institutions IP address ranges change, then these changes must be coordinated with potentially hundreds of publishers. I experienced this problem first hand when I was working for publishers before joining OpenAthens. There were many times that libraries contacted me to update their IP address urgently because their students didn’t have access due to the changing of IP addresses. Another thing we are hearing from librarians is that it is very time consuming to manage these proxy servers. This doesn’t allow them to spend time for more important things such as helping users with their research, looking to purchase more content or replace the resources they subscribe to, etc. In terms of Security IP recognition is highly insecure. IP addresses can be easily spoofed and the institutional networks can be penetrated for illicit downloading. Since IP recognition has no facility for authenticating and authorizing users it’s highly vulnerable for misuse.
  7. We also saw that hacking attempts were increased during Covid the last 3 years since hackers targeted research institutions on a global scale.
  8. Research by one of the biggest publishers found out that more than 90% of compromise is through proxy services. When users find it difficult or complicated to access content they go to places like Sci-Hub. For anyone who doesn’t know what Sci-Hub is, it is an illegal site that gets users to share institution login credentials for access to scholarly research platforms. They steal and openly share login credentials on the dark web and COVID-19 has accelerated the need for increased remote access, increasing security risk
  9. As we saw on the timeline slide earlier there is a protocol called SAML (Security Assertion of Mark-up Language) that was designed for authentication and solves some of the problems the IP recognition causes. But before we talk about SAML and federated authentication I would like to clarify what we mean by single sign-on.
  10. Without a single sign-on system, users need multiple usernames and passwords to access e-journals/e-databases/e-books and other library systems. This is not ideal especially in an online environment where users’ attention span is very short.
  11. Single sign-on solves that problem and offers a much better experience. With one username/password users can access multiple resources as you can see in the diagram above.
  12. As we saw previously SAML started in 2002 and it was designed specifically for authentication –SAML certify users identity. Also, SAML is a standard that is used to exchange information (what we call attributes in SAML) about users with the resources they are accessing while keeping their login details private. SAML is well-established and widely-deployed and uses industry standards and best-practice to digitally sign and encrypt messages to prevent fraudulent use or interception by attackers. Also, most SAML-based systems, allow granular control over what attributes are exchanged with particular resources. This makes SAML not only a more secure alternative to IP recognition but also a more flexible framework for Single Sign-On for many different scenarios
  13. The concept of federated identity management was invented in the research and academic community more than 20 years ago. Alongside the technology, a model for building a fabric of trust has been established, based around the idea of identity management federations. To join a federation, which are typically organized geographically, identity providers and service providers must agree to a set of practices and policies. You have an institution on one side, and a content provider/publisher on the other side.
  14. Federations play an important role in ensuring that standards are being met by Identity Providers and Service Providers alike and that we can trust each other. Federated access is the concept where registered publishers or service providers and institutions put their metadata in the same place. This way publishers and institutions do not need to establish lots of one-to-one connections that they have to maintain. We talked about SAML being the international standard for authentication, but why we need federations in the first place? Can’t we just use SAML? Firstly, SAML is not a plug and play technology. You could task 5 developers to build a set of SAML tools and they would not all operate the same way. Federations were created so that everyone involved adheres to the same policy framework, and technical infrastructure and standards. The key thing about SAML in a federated environment is the deploy once reused multiple times model. It is fully scalable. So, an institution can connect to any publisher that is a member of its federation but more importantly a publisher can deploy once and connect to any participating institution within that same federation.
  15. We noticed that demand from libraries around the world for a secure and modern single sign-on system has increased substantially the last few years. Federated authentication came to the front since it meets lots of libraries and publishers’ criteria. Let’s have a closer look at the specific benefits of federated single sign-on. I would like to start with how the user experience looks like.
  16. Federated single sign-on offers a more seamless access especially for remote users.
  17. Things have changed especially the last few years. Access to library resources from anywhere and on any device has become imperative. Also, products and services such as Google/Netflix/Amazon/Facebook have redefined users’ expectations. Research shows that users nowadays start their journey on Google or Google scholar rather than from the library’s portal. That creates all sort of problems especially if libraries rely on IP recognition to allow access to their subscribed e-resources.
  18. With federated single sign-on users are able to start their search on google or Google scholar and access the content they are looking for with a few clicks. The screenshot here shows that particular scenario. The user looks for an article on Google scholar.
  19. When they find that article they click on the link that can take them to the publisher’s website.
  20. And on the publisher’s website they can access that article via their institutional login button as we can see. It’s a very easy process and one that users are familiar with since it resembles similar patterns when users try to access other services on internet. With IP recognition the user has to start their journey on the library’s portal, which is not ideal since we saw previously that a substantial percentage of users start their research on Google or Google scholar. The increase of remote users due to the pandemic the last 3 years highlighted this functionality and the benefit federated Single Sign-on brings to the end users.
  21. Moving on I would like to delve into how federated single sign-on can benefit libraries. Talking to librarians from different parts of the world we can see that they face challenges when they are looking into what access systems they need to implement. Offering their users the best experience when they access library e-resources is very important. We saw in the previous slide how this is achieved by using a federated single sign-on system. Another challenge librarians face is the maintenance of IP addresses/proxy servers. Very often we hear that libraries have one person working full-time to manage their proxy server. I was in India back in September and a librarian from an academic institution was telling me that because their IT department changed their IP addresses she had to contact all the publishers they subscribed to every year so that they update their system with the new IP addresses. She said that this was very time consuming and not a good use of her time. In terms of efficiency and cost, SAML is a more stable technology and the most modern authentication system available. The ongoing maintenance required is low while a proxy system requires regular, ongoing maintenance as resources change and proxy configurations need updating. Now, some people may wonder that’s fine, but why can’t we use one to one SAML connections?
  22. I included a diagram here to show how it looks when institutions use 1:1 connections. 1:1 connections require more technical involvement to set up and maintain. Libraries that are non-technical/or lack the resources/man power, they need the support of their IT team to set up and maintain direct SAML connections.
  23. The concept of federated authentication reduces the need for one to one connections. In practical terms what happens for example with OpenAthens federation is that we manage all the connections in the Federation so if something needs to be updated (say a security certificate from a publisher) then we’re able to work with the publisher to have that work completed, with the minimal amount of impact. A single change is made centrally and all Federation members benefit, rather than each library managing their own connections and fixing things independently.
  24. Regarding security, IP addresses are easier to spoof while SAML provides a strong set of security tools & policies. With SAML, unauthorised activity is identified early, and user account is blocked. Also, access for other users is not impacted in contrast with IP recognition in which publishers block IPs and users, and an entire university could be without access for hours or even days. We had examples of universities that had incidents every week when they were using a proxy solution and that was one of the reasons they moved to OpenAthens. Federated authentication also preserves user privacy by using persistent opaque identifiers which can only be decoded by the subscribing institution.
  25. We talked how a federated Single Sign-on system can help users and libraries. But what about publishers? Publishers have been adopting federated authentication the last few years for a few reasons: Firstly, publishers want users to be able to get to their content from anywhere on any device seamlessly. Another thing publishers like about federated authentication is that it’s more secure than IP and more suited to protect their content. Now, you may ask, that’s ok but why we don’t use SAML one to one connections or what we call bilateral connections? The reason is that 1-1 connections lead to higher overheads. They require more technical involvement to set up and maintain direct SAML connections as we mentioned previously. Publishers need to liaise with the library and IT team with every library customer that needs a 1:1 SAML connection. This task is technical and very time consuming. Any changes to certificates or metadata can disrupt services for library customers. And any disruption to service could result in poor relationship with library customer and their patrons.
  26. I would like to end the presentation with some of the things I would like you to take from this talk today. Federated authentication is the best technology we have at the moment and it looks like it will be with us for the next few years. Publishers and libraries all around the world are moving away from IP recognition and the pandemic accelerated this trend the last 3 years. Federated single sign-on is based on a robust reliable infrastructure that improves the user experience within a highly secure environment.
  27. Thank you very much and I think we have some time for questions. Jane, do we have any questions
  28. Monday 20 and Thursday 23 March 2023, online.