An Introduction to RA21
Todd Carpenter, Executive Director
National Information Standards Organization (NISO)
NISO Update ALA Annual Conference
June 23, 2018
Behind the scenes:
Does the user have
access rights?
Yes or No?
Do you have a login?
Yes or No?
Where are you from?
??????
And patrons are just getting annoyed
Carpenter Introduction to RA21
RA21 wants to build on the user
experience of the wider web
Make the login experience match the user
experience we’re all familiar with
Private Experience Target Institutional Experience
How SAML Can Protect Privacy
Publishers receive
attributes about the
user, not the user’s
identity.
RA21 Pilots
• Corporate Pilot (Universal Resrource Access “URA”)
•Two Academic Pilots
– Privacy Preserving Persistent WAYF Pilot
– WAYF Cloud Pilot
All seek to address the User Experience for off-campus access
Initial Privacy Review of RA21 Pilots
SECURITY & PRIVACY RECOMMENDATIONS Cloud WAYF P3W
Privacy Policy Requirements √ √
Data Protection Impact Analysis Required √ √
Data Retention Policy Required √
Denial of Service Protection √
Browser security (https + access controls) implementations √ √
Database/data protection best practices √
Server hardening - for security threats √ √
Code Scanning - for security threats √ √
Vulnerability Scanning/Penetration Testing √ √
API security protocols √
Audit Logging and review √
Security Monitoring √
Incident Response Plan √
High Availability Infrastructure requirements √ √
Anti-virus software monitoring √ √
GDPR compliance concerns √
Privacy Preserving Persistent (P3) WAYF Pilot
•Pilot goals
– To improve current Shibboleth Identity Provider discovery process
• Incorporate additional “WAYF hints” such as email domain and IP address into
federation metadata
• Improve sign-in flow using those WAYF hints via a shared discovery service
• Populate shared discovery service hints from the Service Providers regarding
what Identity Providers are likely to work in an authorization scenario
• Enable cross-provider persistence of WAYF choice using browser local storage
•Pilot participants (confirmed so far)
Project Management
GÉANT
Educational Access Management Federations
Sunet & SWAMiD (Swedish Federation)
The samlbits.org project
eduGAIN
EduServ
Publishers
Elsevier
American Chemical Society
Subscribing institutions
MIT
University of California, Davis
University of Arizona (tbc)
University of Denver (tbc)
Service Providers
ProQuest
Ping
LibLynx
Ebsco
Preserving Privacy
Built upon ”SAML-BITS”
technology in production
Technique Challenge
Only domain part of email
address needs to be
transmitted from browser
to publisher platform to
select IDP
Need to define and test a
standardized UI that
makes this clear to users
IdP preference is stored
locally in the browser,
retrieved using centrally
served javascript, not on a
central server
Need to adapt Account
Choose mechanism to
support SAML IdPs vs
OpenID Connect
Authorization Servers
CRITICISM OF RA21
• Yes, SciHub is a motivator of RA21, but not the
only motivator.
• This project began with outreach from LIBRARIES!
• There are a variety of
reasons why libraries
would like to improve
access control
• Evil twins? Come on….
MORE CRITICISM OF RA21
• Open Access is not the end-all be-all of library
access control issues.
– First, even if every journal article were OA, not all
content provided by libraries will be freely available
– Second, a variety of the services that libraries provide
will still need authentication, regardless of whether
they are free or not
– To presume that RA21 is a fight against open access is
to have a very narrow and dim view of what libraries
do and provide.
Google CASA Project
(Campus Activated Subscriber Access)
• Outside of the scope or RA21, but attempting to
address similar questions
• Led by Google Scholar team with several
publisher vendor partners
• Based on Google user-behavior analysis and cloud
data to navigate user to identity provider
• Core question: If you don’t trust RA21’s privacy
protections, do you trust Google to protect
privacy of patrons more than publishers/IdPs?
Carpenter Introduction to RA21
Want to get involved?
•Visit: https://www.RA21.org
•Mailing lists:
–P3W community list: https://lists.refeds.org/sympa/subscribe/p3w-
community
–WAYF Cloud community list: TBD
•Everyone: Register your interest in participation by emailing:
Julie Wallace: Julia@RA21.org and
Heather Flanigan: Heather@RA21.org
Questions?
THANK YOU!
Todd Carpenter
@TAC_NISO
tcarpenter@niso.org

More Related Content

PPTX
RA21 and Privacy - NISO ALA Annual 2018
PPTX
NISO-STM RA21 Project Update
PPTX
The New Dimensions in Scholcomm: How a global scholarly community collaborati...
PPTX
Flanagan, "RA21: What it is, What it isn’t, and What’s Next"
PDF
User Centered E-Resource Management Workflows
PDF
Content Recommendation Through Linked Data
PPTX
Technical introduction to website tracking
PPSX
Vptnhs online information system
RA21 and Privacy - NISO ALA Annual 2018
NISO-STM RA21 Project Update
The New Dimensions in Scholcomm: How a global scholarly community collaborati...
Flanagan, "RA21: What it is, What it isn’t, and What’s Next"
User Centered E-Resource Management Workflows
Content Recommendation Through Linked Data
Technical introduction to website tracking
Vptnhs online information system

What's hot (9)

PPTX
Vptnhs online information system
PDF
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
PPT
Increasing NUS Libraries' Visibility in the Virtual World - Updated
PPTX
ALA NISO Access and License Indicators Lagace
PPTX
BioSharing, an ELIXIR Interoperability Platform resource
PPTX
Technology Evaluation and Meeting the Needs of People with Disabilities
PDF
Overview of standards/stakeholders in life science (RDA Engagement Interest G...
PPTX
Beyer and Hoeppner "Content Platform Migration Working Group Update"
PDF
Streamlining deposit an ojs to repository plugin
Vptnhs online information system
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Increasing NUS Libraries' Visibility in the Virtual World - Updated
ALA NISO Access and License Indicators Lagace
BioSharing, an ELIXIR Interoperability Platform resource
Technology Evaluation and Meeting the Needs of People with Disabilities
Overview of standards/stakeholders in life science (RDA Engagement Interest G...
Beyer and Hoeppner "Content Platform Migration Working Group Update"
Streamlining deposit an ojs to repository plugin
Ad

Similar to Carpenter Introduction to RA21 (20)

PPTX
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
PPTX
RA21 Charleston Library Conference Presentation
PPTX
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
PPTX
PPTX
Flanagan - RA21 Improving Access to Scholarly Resources
PDF
PPTX
Hamparian - IP Authentication for STEM e-Content Access
PPTX
Practical Steps to Address Piracy
PPTX
Chris Shillum: Overview of the RA21 proejct presentation
PPTX
NISO Standards Update, Seamless Access, ALA Midwinter
PPTX
UKSG 2018 Breakout - User-focused authentication and resource access fit for ...
PPT
Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017
PDF
Mina.Deng.PhD.defense
PDF
Mina Deng PhD defense
PPTX
3. w.cellary privacy stockholm_v5
PPT
Privacy and security 815
PDF
Privacy is the Future
PDF
Real World Identity Managment
OpenAthens Conference 2019: Simplifying the SSO User Experience: The RA21 ini...
RA21 Charleston Library Conference Presentation
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
Flanagan - RA21 Improving Access to Scholarly Resources
Hamparian - IP Authentication for STEM e-Content Access
Practical Steps to Address Piracy
Chris Shillum: Overview of the RA21 proejct presentation
NISO Standards Update, Seamless Access, ALA Midwinter
UKSG 2018 Breakout - User-focused authentication and resource access fit for ...
Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017
Mina.Deng.PhD.defense
Mina Deng PhD defense
3. w.cellary privacy stockholm_v5
Privacy and security 815
Privacy is the Future
Real World Identity Managment
Ad

More from National Information Standards Organization (NISO) (20)

PPTX
Larry Bennett_ ALA Annual Convention 2025AL2 slides.pptx
PPTX
Potash "Our Journey & Vision for Accessible Content"
PPTX
O'Leary "Progress Assessment - How Far Are We from Delivery"
PPTX
Carpenter and O'Leary "Accessibility Standards and the Future of Inclusive Pu...
PPTX
Davidian "Transfer Code of Practice Standing Committee Update"
PPTX
Patham "NISO Open Discovery Initiative (ODI) Update"
PPTX
Hichliffe "A Standard Terminology for Peer Review"
PPTX
Levin "KBART RP Update at ALA Annual 2025"
PPTX
Carpenter "Advancing Infrastructure for Sustainable Collections: CCLP Project...
PPTX
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
PPTX
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
PDF
Carpenter "2025 NISO Annual Members Meeting"
PPTX
Allen "Social Marketing in Scholarly Communications"
PPTX
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
PDF
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
PDF
Pfeiffer "Secrets to Changing Behavior in Scholarly Communication: A 2025 NIS...
PPTX
Gilstrap "Accessibility Essentials: A 2025 NISO Training Series, Session 7, M...
PPTX
Turner "Accessibility Essentials: A 2025 NISO Training Series, Session 7, Lan...
PPTX
Comeford "Accessibility Essentials: A 2025 NISO Training Series, Session 7, A...
PPTX
Laverick and Richard "Accessibility Essentials: A 2025 NISO Training Series, ...
Larry Bennett_ ALA Annual Convention 2025AL2 slides.pptx
Potash "Our Journey & Vision for Accessible Content"
O'Leary "Progress Assessment - How Far Are We from Delivery"
Carpenter and O'Leary "Accessibility Standards and the Future of Inclusive Pu...
Davidian "Transfer Code of Practice Standing Committee Update"
Patham "NISO Open Discovery Initiative (ODI) Update"
Hichliffe "A Standard Terminology for Peer Review"
Levin "KBART RP Update at ALA Annual 2025"
Carpenter "Advancing Infrastructure for Sustainable Collections: CCLP Project...
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Carpenter "2025 NISO Annual Members Meeting"
Allen "Social Marketing in Scholarly Communications"
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Pfeiffer "Secrets to Changing Behavior in Scholarly Communication: A 2025 NIS...
Gilstrap "Accessibility Essentials: A 2025 NISO Training Series, Session 7, M...
Turner "Accessibility Essentials: A 2025 NISO Training Series, Session 7, Lan...
Comeford "Accessibility Essentials: A 2025 NISO Training Series, Session 7, A...
Laverick and Richard "Accessibility Essentials: A 2025 NISO Training Series, ...

Recently uploaded (20)

PDF
advance database management system book.pdf
PDF
Complications of Minimal Access-Surgery.pdf
PDF
HVAC Specification 2024 according to central public works department
PDF
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf
PPTX
Unit 4 Computer Architecture Multicore Processor.pptx
PPTX
B.Sc. DS Unit 2 Software Engineering.pptx
PDF
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 2).pdf
PDF
My India Quiz Book_20210205121199924.pdf
PPTX
A powerpoint presentation on the Revised K-10 Science Shaping Paper
PDF
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
PDF
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
PDF
احياء السادس العلمي - الفصل الثالث (التكاثر) منهج متميزين/كلية بغداد/موهوبين
PPTX
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
PPTX
Introduction to pro and eukaryotes and differences.pptx
PDF
International_Financial_Reporting_Standa.pdf
PDF
Trump Administration's workforce development strategy
PDF
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
PDF
Empowerment Technology for Senior High School Guide
PDF
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
PDF
Hazard Identification & Risk Assessment .pdf
advance database management system book.pdf
Complications of Minimal Access-Surgery.pdf
HVAC Specification 2024 according to central public works department
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf
Unit 4 Computer Architecture Multicore Processor.pptx
B.Sc. DS Unit 2 Software Engineering.pptx
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 2).pdf
My India Quiz Book_20210205121199924.pdf
A powerpoint presentation on the Revised K-10 Science Shaping Paper
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
احياء السادس العلمي - الفصل الثالث (التكاثر) منهج متميزين/كلية بغداد/موهوبين
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
Introduction to pro and eukaryotes and differences.pptx
International_Financial_Reporting_Standa.pdf
Trump Administration's workforce development strategy
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
Empowerment Technology for Senior High School Guide
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
Hazard Identification & Risk Assessment .pdf

Carpenter Introduction to RA21

  • 1. An Introduction to RA21 Todd Carpenter, Executive Director National Information Standards Organization (NISO) NISO Update ALA Annual Conference June 23, 2018
  • 2. Behind the scenes: Does the user have access rights? Yes or No? Do you have a login? Yes or No? Where are you from? ??????
  • 3. And patrons are just getting annoyed
  • 5. RA21 wants to build on the user experience of the wider web
  • 6. Make the login experience match the user experience we’re all familiar with Private Experience Target Institutional Experience
  • 7. How SAML Can Protect Privacy Publishers receive attributes about the user, not the user’s identity.
  • 8. RA21 Pilots • Corporate Pilot (Universal Resrource Access “URA”) •Two Academic Pilots – Privacy Preserving Persistent WAYF Pilot – WAYF Cloud Pilot All seek to address the User Experience for off-campus access
  • 9. Initial Privacy Review of RA21 Pilots SECURITY & PRIVACY RECOMMENDATIONS Cloud WAYF P3W Privacy Policy Requirements √ √ Data Protection Impact Analysis Required √ √ Data Retention Policy Required √ Denial of Service Protection √ Browser security (https + access controls) implementations √ √ Database/data protection best practices √ Server hardening - for security threats √ √ Code Scanning - for security threats √ √ Vulnerability Scanning/Penetration Testing √ √ API security protocols √ Audit Logging and review √ Security Monitoring √ Incident Response Plan √ High Availability Infrastructure requirements √ √ Anti-virus software monitoring √ √ GDPR compliance concerns √
  • 10. Privacy Preserving Persistent (P3) WAYF Pilot •Pilot goals – To improve current Shibboleth Identity Provider discovery process • Incorporate additional “WAYF hints” such as email domain and IP address into federation metadata • Improve sign-in flow using those WAYF hints via a shared discovery service • Populate shared discovery service hints from the Service Providers regarding what Identity Providers are likely to work in an authorization scenario • Enable cross-provider persistence of WAYF choice using browser local storage •Pilot participants (confirmed so far) Project Management GÉANT Educational Access Management Federations Sunet & SWAMiD (Swedish Federation) The samlbits.org project eduGAIN EduServ Publishers Elsevier American Chemical Society Subscribing institutions MIT University of California, Davis University of Arizona (tbc) University of Denver (tbc) Service Providers ProQuest Ping LibLynx Ebsco
  • 11. Preserving Privacy Built upon ”SAML-BITS” technology in production Technique Challenge Only domain part of email address needs to be transmitted from browser to publisher platform to select IDP Need to define and test a standardized UI that makes this clear to users IdP preference is stored locally in the browser, retrieved using centrally served javascript, not on a central server Need to adapt Account Choose mechanism to support SAML IdPs vs OpenID Connect Authorization Servers
  • 12. CRITICISM OF RA21 • Yes, SciHub is a motivator of RA21, but not the only motivator. • This project began with outreach from LIBRARIES! • There are a variety of reasons why libraries would like to improve access control • Evil twins? Come on….
  • 13. MORE CRITICISM OF RA21 • Open Access is not the end-all be-all of library access control issues. – First, even if every journal article were OA, not all content provided by libraries will be freely available – Second, a variety of the services that libraries provide will still need authentication, regardless of whether they are free or not – To presume that RA21 is a fight against open access is to have a very narrow and dim view of what libraries do and provide.
  • 14. Google CASA Project (Campus Activated Subscriber Access) • Outside of the scope or RA21, but attempting to address similar questions • Led by Google Scholar team with several publisher vendor partners • Based on Google user-behavior analysis and cloud data to navigate user to identity provider • Core question: If you don’t trust RA21’s privacy protections, do you trust Google to protect privacy of patrons more than publishers/IdPs?
  • 16. Want to get involved? •Visit: https://www.RA21.org •Mailing lists: –P3W community list: https://lists.refeds.org/sympa/subscribe/p3w- community –WAYF Cloud community list: TBD •Everyone: Register your interest in participation by emailing: Julie Wallace: Julia@RA21.org and Heather Flanigan: Heather@RA21.org

Editor's Notes

  • #9: So what are the pilots you ask? We have a Corporate Pilot as well as two academic pilots: The P3W pilot - Privacy Preserving Persistent WAYF Pilot - quite the tongue twister And the WAYF Cloud pilot All seek to address the experience of access outside an institute and to streamline the UX – the user experience – in order to have a similar experience throughout – users do not like to be confronted again and again with new interfaces to master. So following this bit of context for an introduction, we can now go into a bit of detail on the pilots themselves.
  • #10: Two privacy a
  • #11: So onto the first of the Academic pilots: the Privacy Preserving Persistent (P3) WAYF Pilot. There are several important things we are trying to investigate in this pilot: All pilots are addressing the UX in one way or another – If we don’t streamline the UX for authentication, we won’t get endusers to adopt the solution We want to make sure the identity provider discovery is consistent; we have a multiple of science providers participating – the idea is if an enduser selects your identity with one; they won’t have to repeat for the others; but this sharing of information creates a privacy problem, thus we aim for cross-provider persistence of WAYF choice using browser local storage. There is a rather large set of folks collaborating on this; originally two pilots combined. It is managed by Geant, and has participation of several access management Federations, Sunet, EduServ are two examples, as well as publishers and subscribing institutions MIT UC Davis, and many well known service providers: ProQuest, LibLynx, Ebsco
  • #12: So to recap – the P3WAYF pilot would like to make clear to users they only require the domain part of their email (some UX challenges there, but we will solve it), and that their IdP preference is stored locally in the browser, retrieved using centrally served javascript, not on central server.
  • #17: Thank you for your kind attention. We would love to have you involved with any of the pilots. While we currently have a lot of active leadership and participation from the US and UK, we are actively seeking greater involvement from Europe and Australasia. There are a couple of ways you can register your interest: Through our mailing list, or emailing our project leaders directly. We are also happy to answer any questions off line, or connect with me directly Ann Gabriel a.gabriel@Elsevier.com