Shibboleth federations: A Publisher’s Perspective Ale de Vries Product Manager ScienceDirect Elsevier Terena EuroCAMP Malaga, October 18-19, 2006.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

NRL Security Architecture: A Web Services-Based Solution
Inter-Institutional Registration UNC Cause December 4, 2007.
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
Copyright JNT Association 20051Optional Copyright JNT Association Joining the UK Access Management Federation 4th April.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
UC Irvine’s Pre-Shib Attribute Setup PH / QI Directory Provides Authoritative Attribute Store –Had both Faculty / Staff and Student Information UCI’s Campus.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
Shibboleth access management: a replacement for Athens and more? Mark Norman and Christian Fernau OUCS 21 June 2007.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
SWITCHaai Team Federated Identity Management.
AAI with simpleSAMLphp
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Ray Collins27th September 2005LGfL Project – workshop report1 LGfL Project Report Proof of Principle of the Shibboleth Authentication & Authorisation Infrastructure.
Implementing Shibboleth: A Publisher’s Perspective Chris Shillum Vice President, Product Technology Elsevier UKSG Briefing Session 3-4 April 2006.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
Shib in the present and the future Ken Klingenstein Director, Internet2 Middleware and Security.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
PERSEU S : Portal-enabled Resources via Shibbolized End-user Security 3 May 05Spring 2005 Internet2 Member meeting 1 News from the ‘misty’ Albion: Shibboleth.
Mairéad Martin The University of Tennessee September 13, 2015 Federated Digital Rights Management.
1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
GRA Implementations using Open Source Technologies Mark Perbix and Yogesh Chawla SEARCH.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
1 CS 502: Computing Methods for Digital Libraries Lecture 19 Interoperability Z39.50.
Shibboleth at Columbia Update David Millman R&D July ’05
Shibboleth: An Introduction
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
Using Enterprise Logins in Portal for ArcGIS via SAML Greg Ponto & Tom Shippee.
Internet2 Middleware Initiative Shibboleth Ren é e Shuey Systems Engineer I Academic Services & Emerging Technologies The Pennsylvania State University.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation Mark Tysom, JANET(UK) 9 October 2007.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Shibboleth What is it and what is it good for? Chad La Joie, Georgetown University.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
| 1 Open Access Advancing Text and Data Mining Libraries & Publishers working together to support Researchers What is Text Mining?
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Towards a Unified Authentication, Authorisation and Accounting Infrastructure Patrick Kirk Chief Technical Officer (YHGfL) Lifelong Learning Infrastructure.
Mairéad Martin The University of Tennessee December 16, 2015 Federated Digital Rights Management.
The UK Access Management Federation John Chapman Project Adviser – Becta.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation TNC - 22 nd May 2007 Mark Tysom, UKERNA.
Shibboleth Trust Model Shibboleth/SAML Communities (aka Federated Administrations) Club Shib Club Shib Application process Policy decision points at the.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Shibboleth & Federated Identity A Change of Mindset University of Texas Health Science Center at Houston Barry Ribbeck
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Interfederation RL “Bob” Morgan University of Washington and Internet2 Internet2 Member Meeting Chicago, Illinois December 2006.
InCommon® for Collaboration Institute for Computer Policy and Law May 2005 Renee Shuey Penn State Andrea Beesing Cornell David Wasley Internet 2.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Shibboleth for Middle Schools James Burger -
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
InCommon Steward Program: Community Review
e-Infrastructure Workshop 28th March 2006, University of Leeds
Federated Digital Rights Management
JSTOR as a Shibboleth Target
Shibboleth 2.0 IdP Training: Introduction
Presentation transcript:

Shibboleth federations: A Publisher’s Perspective Ale de Vries Product Manager ScienceDirect Elsevier Terena EuroCAMP Malaga, October 18-19, 2006

2 About me  Ale: “Aah-luh”. Nothing to do with beer. Really.  Product Manager for ScienceDirect, a.o. authentication, interoperability, library integration  Service Provider  Not a techie

3

4 Agenda The impact of belonging to multiple federations from a vendor’s perspective  ScienceDirect background  Our thoughts on authentication  History of  Business and policy issues  Challenges and the future

5 Elsevier’s primary online platform for full-text content  Originally only locally hosted content (1994 onwards)  1999: commercial launch of online platform: Some facts:  >2,000 journals, >160 Book Series, 50 reference works  Advanced browse and search, personalized alerts, history  Extensive article and entity linking, federated searching  Supports institutional subscriptions and individual article purchases

6 ScienceDirect background

7 Our imperative No matter what, we will always provide...: - anonymous blanket access - optional personalized services in exchange of basic registration... using whatever methods are common practice with our customers

8 Shib benefits as we see them  Replacement for IP authentication for on-site access  Remote access! and personalization using local credentials (no more post- its)  Bottom line: helps us provide the broadest possible access to our customers’ user communities

9 Shib & SD history: ramp-up…  April 2002: Attended DLF/CNI workshop at NYU  Held workshops with to involve customers and Internet 2 in the design process:  Findings:  Anonymous non-personalized access a must  Provide option to personalize if an opaque, unique user identifier supplied (targeted ID) via normal end- user registration  Needed support for deep linking  May 2004: Initial Shib release  Support for a single Federation …initially InQueue  Based on Shib v1.1 software

10 Shib & SD history: … testing…  May-Dec 2004: Pilot test  Participants: Dartmouth; Georgetown; NYU; UCSD; Penn State  Pilot aims:  To determine what it takes to get campuses up and running with authentication via Shibboleth.  To determine what end-user issues arise form the Shibboleth implementation on ScienceDirect.  No major problems getting up and running  Some issues with attributes, release policies, firewalls  None of the pilot participants rolled out access to broad user community

11 Shib & SD history: … production!  Feb 2005: Moved in InCommon (US Production Federation)  First vendor to use InCommon in production  July 2005: Multi-federation support released  Held more design workshops - findings: » Need flexibility in which attribute assertions to request, according to Federation rules » Main issue is branding and IdP discovery in a multi-federation world » We have to know which WAYF to send user to…

12 The business side of things  Policies  Legal framework  User flow with multiple federations

13 Our policy (>90% of our licenses): All authorized users can use ScienceDirect under a site license

14 Authorized users: Full-time and part-time students, faculty, staff, researchers, and independent contractors of the Subscriber affiliated with the Subscriber’s locations, and individuals using computer terminals within the library facilities at the Sites permitted by the Subscriber to access the Licensed Products through the Subscriber’s secure network. = pretty much anyone that the customer trusts

15 Policies Where are you from? = All we need to know urn:mace:dir:entitlement:common-lib-terms

16 Legal stuff  Trust relationship between Elsevier and IdP: covered by SD license  Trust relationship between Elsevier and user: covered by Terms & Conditions and Privacy Policy  Trust relationship between Elsevier and Federation: ?

17 Legal stuff What’s to be trusted? - Safe end user data - Stable infrastructure - Up-to-date metadata - Good performance - No abuse - Intellectual property - Nobody backs out Not much to protect under current model Not really an issue with small-scale federations (pilots)

18 Legal stuff Our approach:  Small-scale federations and pilots: no formal agreement (keep the lawyers out ;-) )  Production-strength, full-scale federations: have at least SOME form of documented agreement covering the essentials

19 Multiple federations

20 The WAYF issue  WAYF page: from what institution are you?  Normally operated by federation  Multi-federation support means: from what federation are you?  No-one runs a WAYF of WAYFs  End users don’t understand the federation concept … but federations are geographically oriented!  Elsevier’s solution: implement WAYF- functionality inside ScienceDirect  Label federations geographically

21

22 Demo (or not)

23 Confederating = Inter-federating ? (...because it’s simplest?)

24 Driving Adoption What can federations do:  Standardisation across federations is needed to ease SP implementation, especially  Attribute syntax and semantics (good progress recently!)  Certificates  Metadata distribution policy  IdP granularity  Advice: do what’s been done before, don’t reinvent the wheel

25 Driving Adoption What should publishers do:  Act now!  Get in touch with your customers and the community  Understand the concepts and architecture  Understand the benefits  Added value for users  Business models  Operational efficiencies  Piracy

26 Final thoughts  Technology complex and still evolving  Federations still getting their feet wet  Need to make implementation easier for smaller customers and vendors  Elsevier will stick to this  What will make this fly?

Thank you – Any Questions! Further information: Technology: Chris Shillum Product Manager: Ale de Vries

End of presentation…