SlideShare a Scribd company logo
openathens.org
Preserving user privacy and protecting online
content
Adam Snook
Product manager
openathens.org
Please use the ‘Raise your hand’
button, found on your control panel,
to indicate that you can hear the
audio
openathens.org
To ask our speakers a question, please enter them here
openathens.org
Preserving user privacy and protecting online
content
Adam Snook
Product manager
Webinar - 27 February 2019
openathens.org
What we’ll cover
What is federated single sign-on?
How can it preserve user privacy?
How it protects valuable subscribed content?
What is the future of access to online
information?
More information and next steps
openathens.org
What is federated single sign-on?
Adam Snook
Product manager
openathens.org
What is federated
single sign-on?
Three-way trust relationship between a library user, their
organisation and content provider
Organisation manages user consent and authentication
Content provider manages access rights and authorisation of
access to content
OpenAthens provides the eco-system where encrypted user attributes are
exchanged between organisation and content provider, securely and seamlessly
Webopedia definition
Federated Access
Service ProvidersIdentity Providers
Providing the user’s identity. I.e.
their email address and
subscribed resources.
Providing paid-for content to
organisations and their users.Authentication vs Authorisation
“We confirm this user
is a student from our
Biology department”
“Biology students from your
institution can only access our
Biology content”
attributes
SAML ‘Handshake’
openathens.org
Preserving user privacy
openathens.org
openathens.org
Data Protection Code of Conduct
• Service providers must comply with data protection legislation
• Supported by RA21, the Code of Conduct principles include:
o Minimising the attribute data released to service providers
o Restricting attribute data to enabling access, unless user consent has been obtained
(directly or via the user’s organisation)
o Deleting/anonymising attribute data when no longer necessary
o No transfer of attribute data to another service, except if mandated for enabling
access on behalf of the service provider, the third party also complies with data
protection, and prior user consent is obtained
o Security measures to safeguard user attributes
• bit.ly/GEANTdp
openathens.org
How does OpenAthens handle privacy?
Our privacy statement:
• What information we collect
• What we do with that information
• How we protect it
• How long we keep it for
• How you can check your information
• openathens.org/privacy/
openathens.org
Library organisations - your responsibilities
• Processing of user data must be fair, lawful, necessary and proportionate to the
purpose(s) for which data is required.
• Organisations must inform users what their personal data will be used for at the time it is
collected.
• Users can ‘opt out’ of providing personally identifiable information.
• Organisations must ensure personal data is not misused and only released to service
providers when necessary.
• User consent may be requested for additional personal data. Users can change their
minds and change or stop future release of this information.
openathens.org
Privacy challenges for librarians
• Blog: Opportunities and challenges for
librarians created by technology
• EBSCO long overdue podcast
“Some providers have gone so far
as to provide personalisation
without using any personally
identifiable information
whatsoever.”
openathens.org
Protecting privacy through user attributes
Attribute Description
eduPersonScopedAffiliation User’s association with the organisation e.g. student,
researcher, staff, alumni, walk-in, affiliate
eduPersonTargetedID An opaque, persistent and pseudonymous identifier
used for personalisation. Unique to each user, it does
not contain any information that can identify a person.
eduPersonEntitlement Describes the resource set the user is entitled to
access.
openathens.org
User managed consent
• Users can accept release of
attributes to service providers using
Shibboleth Identity Provider v3
• Attributes may include
eduPersonPrincipalName
• Openathens plans to support
user managed consent and multi-
factor authentication in the future
openathens.org
Protecting content
openathens.org
IP-based access
• Sometimes results in users providing personal information to publishers
• Difficult to track who your users are
• Inconsistent user journey off-site, so users choose the easy route e.g.
sharing content with friends or colleagues, or access via pre-print
repositories, ResearchGate and SciHub
• Fewer visits to your website potentially impacts library subscription decisions
openathens.org
Federated single sign-on
• Trust model – more secure
• Users less likely to share their credentials
• Library verifies who the user is
• You trust the library
• Seamless user journey to all the library’s subscribed content
• Users less likely to visit other nefarious sites
• Can request personally identifiable information from users with their consent
e.g. eduPersonPrincipalName
openathens.org
OpenAthens Conference, 19 March 2019, London
Panel debate: Piracy as a disruptor for
change
Further reading:
How piracy is forcing industry
transformation
Emily Powell, College of Policing Phil Leahy, OpenAthens
Date
SIMPLE, TRUSTED ACCESS –
ANYWHERE, ANYTIME, ON ANY DEVICE
www.ra21.org
openathens.org
What is RA21?
• Resource Access for the 21st Century (RA21) is a joint STM and NISO initiative
with goals to:
o Facilitate a seamless user experience for consumers of scientific
communication.
o Solve long standing and complex challenges in the areas of network
security and user privacy.
• Universal agreement that there needs to be alternatives to IP authentication.
• Aiming for adoption of RA21 recommendations globally.
openathens.org
Myth Busting: Five Commonly
Held Misconceptions About
RA21 (and One Rumor
Confirmed)
UX Building Blocks
2
Consistent visual cue
and call to action signals
institutional access
Flexible and smart search
• Search by institution name,
abbreviation or email
• Typeahead matching and URL
Remembered institution
on next access1 2 3
RA21 UX Goals
2
A user only encounters a
discovery process once
(per browser).
The user’s institution is persisted
in browser local storage and
subsequently rendered in the
RA21 button across all
participating publishers.
1 2
openathens.org
Main outputs
1. Set of recommendations that build on NISO’s ESSPReSSO recommended
practice
2. Establish a new governance structure
3. Launch a new service that simplifies access for users
Main outcome
• Expectation that publishers will start to deploy RA21 recommended practices in
second half of 2019.
openathens.org
OpenAthens Conference, 19 March 2019, London
Guest blog: Todd Carpenter, NISO
outlines the work of RA21 to simplify
access
openathens.org
Simplifying access with
OpenAthens Wayfinder
openathens.org
Example of a poor user journey
openathens.org
Wayfinder
openathens.org
What data does the publisher see?
openathens.org
Wayfinder
development
Embeddable and pop-up versions on their
way
Help us to develop Wayfinder
Feedback on integration and new features
contact@openathens.net
openathens.org
Questions?Q&A – over to you
openathens.org
More information
Adam Snook
adam.snook@openathens.net
Product manager
openathens.org
• Download the free ebook which includes
explanations and guides on:
• The difference between authentication and
authorisation
• Web based authentication
• IP address recognition
• What SAML is and how it works
• OpenID Connect
• Basic troubleshooting
openathens.org
This report presents the key findings from
over 900 responses including:
• Access management is critical to meeting
users needs
• Increased demand for mobile or off-site
access
• Library staff requiring greater technical
expertise than ever before
• The need to help users with their digital
skills
openathens.org

More Related Content

PPTX
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
PDF
Tracking the Trackers tutorial at the Digital Methods Summer School 2013
PPTX
Quick wins for an easier user journey
PPT
The Tools of Web 2.0
PPT
Web 2.0 in Libraries: Theory and Practice
PPT
RSS and Social Bookmarking
PPT
Online Community & Libraries
PPT
Social Bookmarking
OpenAthens Conference 2018 - Neil Scully and Martyn Jansen - Protecting the user
Tracking the Trackers tutorial at the Digital Methods Summer School 2013
Quick wins for an easier user journey
The Tools of Web 2.0
Web 2.0 in Libraries: Theory and Practice
RSS and Social Bookmarking
Online Community & Libraries
Social Bookmarking

What's hot (11)

PPT
web 1.0, 2.0, 3.0
PPTX
What is Web 3.0?
PPT
Web 3.0 (Presentation)
PPTX
Organise your life and create frameworks with a digital library (schoolnetsa11)
PPT
Library 2.0 And Web 2.0
PPT
Why Web 2.0?
PPTX
Hyperlinks
PPTX
Internet Privacy
PPT
Emerging Trends and Technologies
PPT
What is internet
PDF
The Web: history - now - future
web 1.0, 2.0, 3.0
What is Web 3.0?
Web 3.0 (Presentation)
Organise your life and create frameworks with a digital library (schoolnetsa11)
Library 2.0 And Web 2.0
Why Web 2.0?
Hyperlinks
Internet Privacy
Emerging Trends and Technologies
What is internet
The Web: history - now - future
Ad

Similar to Webinar: Preserving user privacy and protecting online content (20)

PPTX
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
PPTX
Are you giving your users the best online experience - Webinar
PPTX
UKSG 2018 Breakout - User-focused authentication and resource access fit for ...
PPTX
Jon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
PPTX
When bad user experience creates a barrier to content
PPTX
Introducing OpenAthens Cloud for content providers
PPTX
OpenAthens Cloud - Global access to your digital content
PDF
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
PDF
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
PPTX
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
PDF
Access Lab 2020: FOLIO + OpenAthens integration
PPTX
What can SAML / Shibboleth do for your institution?
PPTX
Key considerations when mapping your end user experience
PPT
OpenAthens and the future of access and identity management
PPTX
Leahy - What can SAML/Shibboleth do for your institution?
PPTX
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
PDF
Leahy Transforming the User Experience with Identity Management and SSO
PPSX
Beyond Library eResources: Using OpenAthens for Enterprise Security
PPTX
Librarian's experiences
PPTX
Doing Authentication
OpenAthens Conference 2018 - Adam Snook - Quick wins for an easier user journ...
Are you giving your users the best online experience - Webinar
UKSG 2018 Breakout - User-focused authentication and resource access fit for ...
Jon Bentley - UK federation & Shibboleth Consortium Publisher Meeting
When bad user experience creates a barrier to content
Introducing OpenAthens Cloud for content providers
OpenAthens Cloud - Global access to your digital content
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
Singley "Building Privacy Infrastructure - An Academic Library’s Perspective"
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
Access Lab 2020: FOLIO + OpenAthens integration
What can SAML / Shibboleth do for your institution?
Key considerations when mapping your end user experience
OpenAthens and the future of access and identity management
Leahy - What can SAML/Shibboleth do for your institution?
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
Leahy Transforming the User Experience with Identity Management and SSO
Beyond Library eResources: Using OpenAthens for Enterprise Security
Librarian's experiences
Doing Authentication
Ad

More from OpenAthens (20)

PDF
Envisioning the future of AI in research libraries
PPTX
The importance of UX for librarians
PPTX
How to handle publisher requests for PII
PPTX
Privacy, security and browser changes
PPTX
Cybersecurity webinar: Their risk is our risk
PPTX
Webinar - Making the business case - resources.pptx
PPTX
Library user experience report: Removing barriers in the search for knowledge
PPTX
Access interrupted? How changes in browser technology may impact researchers'...
PPTX
What is federated single sign-on?
PPTX
IOP Publishing - How we simplified user access
PPTX
Introduction to SeamlessAccess
PPTX
APAN50 - Removing barriers to knowledge
PPTX
Access Lab 2020: OpenAthens product roadmap
PPTX
Access Lab 2020: OpenAthens and Alma implementation
PPTX
Access Lab 2020: Switching from EzProxy to OpenAthens
PPTX
Access Lab 2020: Helping users get on the right path even if they start off o...
PPTX
Access Lab 2020: From raw content assets to personalised, digital products
PPTX
Access Lab 2020: Librarians are users too
PPTX
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
PDF
Access Lab 2020: Change of identity, loss of personalisation?
Envisioning the future of AI in research libraries
The importance of UX for librarians
How to handle publisher requests for PII
Privacy, security and browser changes
Cybersecurity webinar: Their risk is our risk
Webinar - Making the business case - resources.pptx
Library user experience report: Removing barriers in the search for knowledge
Access interrupted? How changes in browser technology may impact researchers'...
What is federated single sign-on?
IOP Publishing - How we simplified user access
Introduction to SeamlessAccess
APAN50 - Removing barriers to knowledge
Access Lab 2020: OpenAthens product roadmap
Access Lab 2020: OpenAthens and Alma implementation
Access Lab 2020: Switching from EzProxy to OpenAthens
Access Lab 2020: Helping users get on the right path even if they start off o...
Access Lab 2020: From raw content assets to personalised, digital products
Access Lab 2020: Librarians are users too
Access Lab 2020: Saying ‘no’ the publisher’s personal data gathering – our ex...
Access Lab 2020: Change of identity, loss of personalisation?

Recently uploaded (20)

PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Cloud computing and distributed systems.
PDF
Modernizing your data center with Dell and AMD
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
cuic standard and advanced reporting.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Unlocking AI with Model Context Protocol (MCP)
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Cloud computing and distributed systems.
Modernizing your data center with Dell and AMD
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
cuic standard and advanced reporting.pdf
MYSQL Presentation for SQL database connectivity
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Chapter 3 Spatial Domain Image Processing.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Spectral efficient network and resource selection model in 5G networks
Diabetes mellitus diagnosis method based random forest with bat algorithm
Mobile App Security Testing_ A Comprehensive Guide.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
20250228 LYD VKU AI Blended-Learning.pptx
Understanding_Digital_Forensics_Presentation.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf

Webinar: Preserving user privacy and protecting online content

  • 1. openathens.org Preserving user privacy and protecting online content Adam Snook Product manager
  • 2. openathens.org Please use the ‘Raise your hand’ button, found on your control panel, to indicate that you can hear the audio
  • 3. openathens.org To ask our speakers a question, please enter them here
  • 4. openathens.org Preserving user privacy and protecting online content Adam Snook Product manager Webinar - 27 February 2019
  • 5. openathens.org What we’ll cover What is federated single sign-on? How can it preserve user privacy? How it protects valuable subscribed content? What is the future of access to online information? More information and next steps
  • 6. openathens.org What is federated single sign-on? Adam Snook Product manager
  • 7. openathens.org What is federated single sign-on? Three-way trust relationship between a library user, their organisation and content provider Organisation manages user consent and authentication Content provider manages access rights and authorisation of access to content OpenAthens provides the eco-system where encrypted user attributes are exchanged between organisation and content provider, securely and seamlessly Webopedia definition
  • 8. Federated Access Service ProvidersIdentity Providers Providing the user’s identity. I.e. their email address and subscribed resources. Providing paid-for content to organisations and their users.Authentication vs Authorisation “We confirm this user is a student from our Biology department” “Biology students from your institution can only access our Biology content” attributes SAML ‘Handshake’
  • 11. openathens.org Data Protection Code of Conduct • Service providers must comply with data protection legislation • Supported by RA21, the Code of Conduct principles include: o Minimising the attribute data released to service providers o Restricting attribute data to enabling access, unless user consent has been obtained (directly or via the user’s organisation) o Deleting/anonymising attribute data when no longer necessary o No transfer of attribute data to another service, except if mandated for enabling access on behalf of the service provider, the third party also complies with data protection, and prior user consent is obtained o Security measures to safeguard user attributes • bit.ly/GEANTdp
  • 12. openathens.org How does OpenAthens handle privacy? Our privacy statement: • What information we collect • What we do with that information • How we protect it • How long we keep it for • How you can check your information • openathens.org/privacy/
  • 13. openathens.org Library organisations - your responsibilities • Processing of user data must be fair, lawful, necessary and proportionate to the purpose(s) for which data is required. • Organisations must inform users what their personal data will be used for at the time it is collected. • Users can ‘opt out’ of providing personally identifiable information. • Organisations must ensure personal data is not misused and only released to service providers when necessary. • User consent may be requested for additional personal data. Users can change their minds and change or stop future release of this information.
  • 14. openathens.org Privacy challenges for librarians • Blog: Opportunities and challenges for librarians created by technology • EBSCO long overdue podcast “Some providers have gone so far as to provide personalisation without using any personally identifiable information whatsoever.”
  • 15. openathens.org Protecting privacy through user attributes Attribute Description eduPersonScopedAffiliation User’s association with the organisation e.g. student, researcher, staff, alumni, walk-in, affiliate eduPersonTargetedID An opaque, persistent and pseudonymous identifier used for personalisation. Unique to each user, it does not contain any information that can identify a person. eduPersonEntitlement Describes the resource set the user is entitled to access.
  • 16. openathens.org User managed consent • Users can accept release of attributes to service providers using Shibboleth Identity Provider v3 • Attributes may include eduPersonPrincipalName • Openathens plans to support user managed consent and multi- factor authentication in the future
  • 18. openathens.org IP-based access • Sometimes results in users providing personal information to publishers • Difficult to track who your users are • Inconsistent user journey off-site, so users choose the easy route e.g. sharing content with friends or colleagues, or access via pre-print repositories, ResearchGate and SciHub • Fewer visits to your website potentially impacts library subscription decisions
  • 19. openathens.org Federated single sign-on • Trust model – more secure • Users less likely to share their credentials • Library verifies who the user is • You trust the library • Seamless user journey to all the library’s subscribed content • Users less likely to visit other nefarious sites • Can request personally identifiable information from users with their consent e.g. eduPersonPrincipalName
  • 20. openathens.org OpenAthens Conference, 19 March 2019, London Panel debate: Piracy as a disruptor for change Further reading: How piracy is forcing industry transformation Emily Powell, College of Policing Phil Leahy, OpenAthens
  • 21. Date SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY DEVICE www.ra21.org
  • 22. openathens.org What is RA21? • Resource Access for the 21st Century (RA21) is a joint STM and NISO initiative with goals to: o Facilitate a seamless user experience for consumers of scientific communication. o Solve long standing and complex challenges in the areas of network security and user privacy. • Universal agreement that there needs to be alternatives to IP authentication. • Aiming for adoption of RA21 recommendations globally.
  • 23. openathens.org Myth Busting: Five Commonly Held Misconceptions About RA21 (and One Rumor Confirmed)
  • 24. UX Building Blocks 2 Consistent visual cue and call to action signals institutional access Flexible and smart search • Search by institution name, abbreviation or email • Typeahead matching and URL Remembered institution on next access1 2 3
  • 25. RA21 UX Goals 2 A user only encounters a discovery process once (per browser). The user’s institution is persisted in browser local storage and subsequently rendered in the RA21 button across all participating publishers. 1 2
  • 26. openathens.org Main outputs 1. Set of recommendations that build on NISO’s ESSPReSSO recommended practice 2. Establish a new governance structure 3. Launch a new service that simplifies access for users Main outcome • Expectation that publishers will start to deploy RA21 recommended practices in second half of 2019.
  • 27. openathens.org OpenAthens Conference, 19 March 2019, London Guest blog: Todd Carpenter, NISO outlines the work of RA21 to simplify access
  • 29. openathens.org Example of a poor user journey
  • 31. openathens.org What data does the publisher see?
  • 32. openathens.org Wayfinder development Embeddable and pop-up versions on their way Help us to develop Wayfinder Feedback on integration and new features contact@openathens.net
  • 35. openathens.org • Download the free ebook which includes explanations and guides on: • The difference between authentication and authorisation • Web based authentication • IP address recognition • What SAML is and how it works • OpenID Connect • Basic troubleshooting
  • 36. openathens.org This report presents the key findings from over 900 responses including: • Access management is critical to meeting users needs • Increased demand for mobile or off-site access • Library staff requiring greater technical expertise than ever before • The need to help users with their digital skills

Editor's Notes

  • #12: Pan-European network for research & education. Must have sec measures in place to safeguard Opaque identifiers are allowed for the purpose of recognising a returning user, but not their individual identity
  • #13: iso27001
  • #24: Myth 1: IP authentication is privacy preserving, where federated authentication technologies are not. BUSTED Myth 2: Proxy servers work just fine as a solution for off-campus access. BUSTED Myth 3: RA21 wants to enable publishers to track users across each other’s platforms. BUSTED Myth 4: RA21 creates yet another username and password. BUSTED Myth 5: RA21 is placing control of users’ identity in the hands of institutions and not the individuals themselves. PLAUSIBLE Myth 6: RA21 seeks to eliminate IP-based access. CONFIRMED
  • #25: Ralph
  • #26: Ralph