simple, trusted access – anywhere, anytime, on any … · eduserv elsevier publishing emerald...

28
January 17, 2019 SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY DEVICE Ralph Youngen, American Chemical Society Co-Chair of RA21 DFG Round Table – Berlin, Germany

Upload: others

Post on 11-Jul-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

January 17, 2019

SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY DEVICE

Ralph Youngen, American Chemical SocietyCo-Chair of RA21

DFG Round Table – Berlin, Germany

Page 2: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

Background• RA21 has roots back to 2015

with a movement from corporate librarians as represented by the Pharma Documentation Ring (P-D-R).

– Indicated that IP address recognition as a means of providing services to corporate researchers was no longer meeting their needs.

2

Page 3: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

What we decided we would need…

1. SOLUTION

Single Sign On (SSO) Open Standards (eg SAML) Inside/Outside Network

1. SOLUTION

Single Sign On (SSO) Open Standards (eg SAML) Inside/Outside Network

2. PUBLISHER SUPPORT

Standard Adopted by All STM Publishers

Granular Usage Stats Privacy & Security

2. PUBLISHER SUPPORT

Standard Adopted by All STM Publishers

Granular Usage Stats Privacy & Security

Page 4: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

Background (cont.)

• June 2015: P-D-R holds a special meeting on Authentication Technologies

• June 2016: Copyright Clearance Center hosts Universal Resource Access Forum involving P-D-R members, publishers, software providers, etc.

• July 2016: URA Task Force was formed

• Mid-2016: STM forms parallel effort, RA21, in partnership with NISO

• End of 2016: URA Task Force becomes Corporate Pilot of RA21

4

Page 5: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

• Individuals from more than 60 different organizations have been involved in RA21 since its inception in late 2016.

5

AbbVie PharmaceuticalsAmerican Medical Association / JAMAAmerican Chemical SocietyAmerican University American Psychological AssociationAssociation of Research Libraries American Society of Civil EngineersAtypon SystemsBASFBibliotheksservice-ZentrumBrill PublishersBrown UniversityCentre for Agriculture and BioscienceCarnegie Mellon UniversityClarivate AnalyticsCambridge University PressCopyright Clearance CenterDenver UniversityEBSCO Information ServicesEduservElsevier PublishingEmerald Publishing GroupErasumus University RotterdamETHZ

GEANTGlaxoSmithKline PharmaceuticalsHarvardHighwire PressHypothes.isIEEEInformed Strategies LLCInternet2Institute of Physics PublishingJISCJohns Hopkins UniversityKTH Royal Institute of TechnologyLiblynxMITMyUniDysNISONovartisOCLCOpen UniversityORCIDOpitcal Society of AmericaOxford University Press ProquestRinggold

Roche Holding AGGSage PublicationsSilverchair Information SystemsSpringer NatureSTMSUNETSwitchTaylor & Francis GroupThieme Medical PublishersTilburg UniversityUC DavisUniversiti Putra MalaysiaUniversity at BuffaloUniversity of BathUniversity of NottinghamUniversity of SurreyWileyWolters Kluwer Publishing

Corporation Corporation

Academic Institution Academic Institution

Software/Service ProviderSoftware/Service Provider

PublisherPublisher

RA21 Industry Participation

Page 6: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

The need for RA21

Simple access to content

needs to be fixed,

especially for off campus use:

•Scholarly content & services are increasingly being accessed from outside of corporate/campus networks•Publisher pathways for providing off-network access have not kept pace with our experience on the consumer web (e.g. Google, Facebook, LinkedIn logins across multiple sites).•When accessing publisher platforms off-network, fully entitled end users are turning to alternative resources (e.g. SciHub, etc.) because of ease of access.•RA21 has been established as the first step in the journey towards replacing the now outdated IP based access & authentication model.

6

Mobile Traffic in Visits

Page 7: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

• VPN/Proxy Servers

Current Off-Campus Solutions are Unsatisfactory

7

Page 8: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

• Device Pairing

• VPN/Proxy

Current Off-Campus Solutions are Unsatisfactory

8

Page 9: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

• Device Pairing

• Other “Access Brokers”

• VPN/Proxy

Current Off-Network Solutions are Unsatisfactory

9

Campus Activated Subscriber Access (CASA)

Page 10: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

• Device Pairing

• Access Brokers

• VPN/Proxy

Current Off-Network Solutions are Unsatisfactory

10

All Leverage Institutional IP Address Recognition

All Require User Setup In Advance

Page 11: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 vs. “Access Brokers”Position statement was published contrasting RA21 with “Access Brokers” (e.g. Kopernio, Anywhere Access, and CASA)

11

Typically require creation of individual user accounts, potentially compromising privacy.

RA21 follows long-standing practices in scholarly federated identity management in the academic sector by providing the option for users to remain anonymous.

Often capture and store a copy of the user’s institutional username and password, potentially creating a security risk.

RA21 ensures that the user’s institutional username and password are only visible to the user’s home institution.

Are often paid services, provided by libraries and configured by end users.

RA21 will be free for subscribing institutions and require no configuration on behalf of end users.

Access Brokers may enable the provider of the software/solution to gain insights on end user behavior and reading habits across publisher sites.

RA21’s decentralized, federated model provides no mechanism for tracking user behavior across publisher sites.

Must be installed or configured by end users prior to starting a research discovery journey. Must be installed on all devices under the user’s control.

RA21 eliminates the need for any additional software or end user configuration. RA21 will ensure simple access to scholarly resources from anywhere, on any device, at any time.

“Access Brokers” RA21

Page 12: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

Surely there is a better way…

Access to scholarly content, especially off-network, needs to be fixed

• Federated authentication using SAML (“Shibboleth”) solves most of the problem– Multilateral trust

– Mature technology

– Widely deployed and supported by scholarly information providers

– Widely adopted and deployed by academic institutions

– Increasingly deployed by corporate customers given the rise of SaaS platforms (if you’ve signed into Slack recently, you’ve used SAML!)

12

Page 13: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

“Every researcher is entitled to focus on their work and not be impeded by needless obstacles nor required to understand anything about the FIM infrastructure enabling their access to research services. The recommendations … highlight well-established practices … whose widespread adoption would represent a huge boost to usability of federated access mechanisms by users engaged in collaborative research activities.”

“Every researcher is entitled to focus on their work and not be impeded by needless obstacles nor required to understand anything about the FIM infrastructure enabling their access to research services. The recommendations … highlight well-established practices … whose widespread adoption would represent a huge boost to usability of federated access mechanisms by users engaged in collaborative research activities.”

Strong support among the research community for federated identity management to improve collaboration

• FIM4R.org has produced two whitepapers recommending

improvements to the federated identity infrastructure to

support research collaboration

• Participants include

– CLARIN, European Research Infrastructure for Language Resources and Technology

– DARIAH, Digital Research Infrastructure for the Arts and Humanities

– ELIXIR, Life Sciences

– ESA, European Space Agency

– INAF, Italian National Institute for Astrophysics

– LIGO, Laser Interferometer Gravitational-Wave Observatory

– Umbrella, Photon and Neutron Science

– WLCG, Worldwide LHC Computing Grid (High Energy Physics)

13

https://fim4r.org/wp-content/uploads/2018/06/FIM4R-version-2-final-draft-20180611.pdf

Page 14: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

So why RA21?

The current institutional discovery workflow is very difficult for users to navigate

14

Page 15: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 UX Challenge• Seeks to implement seamless, convenient access to scholarly content

while still preserving user privacy.

15

Typical Research Discovery Workflow On Network

Page 16: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 UX Challenge• Seeks to implement seamless, convenient access to scholarly content

while still preserving user privacy.

16

Typical Research Discovery Workflow Off Network

InstitutionalRepositories

Email theAuthor

Page 17: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 UX Challenge• Seeks to implement seamless, convenient access to scholarly content

while still preserving user privacy.

17

Typical Research Discovery Workflow Off Network

Page 18: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

Preserving Privacy

18

User: 12345Role: Student

User: 56789Role: Student

User: 55555Role: Student

Publishers receive attributes about the user, not the user’s identity.

Page 19: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

New Capabilities with Attributes

19

Accessing Content

Page 20: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

New Capabilities with Attributes

20

Paying OA Fees

£ € $

Page 21: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 GoalsRecommend new solutions for access strategies beyond IP recognition in joint collaboration with software vendors, libraries, federation operators, publishers and service providers

• Test and improve solutions by organizing pilots in a variety of environments

• Establish best practices and publish via the NISO Recommended

Practice process – in process, UX demo today

• Prepare for post-project phase by identifying potential parties to

operate any necessary centralized infrastructure – in process

21

Page 22: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 Current Status

22

Published in July 2018.

Corporate Pilot

WAYF Cloud

Work on pilots has concluded.Corporate Pilot report was published in September 2018.Academic Pilot report was published in July 2018. - P3W architecture was selected.

Refinement and user testing continues, demo today.

Page 23: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 Security / Privacy Analysis

Objective:

– Assess security and privacy risks associated with the technical architectures that were tested by the two pilots

– Provide recommendations tailored to mitigate risks identified for each

Methodologies used:

23

STRIDE Threat Model for security • Spoofing Identity

• Tampering with Data

• Repudiation

• Information Disclosure

• Denial of Service

• Elevation of Privilege

DPIA for privacy • Data Protection Impact Analysis

• Performed in compliance with GDPR

Page 24: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 Security / Privacy Conclusion

• There are no significant risks which prevent RA21 from moving forward

• Residual risks from both security and privacy perspectives are LOW

• The nature of the data involved is low value, i.e., not directly or easily attributable to any natural person

• Appropriate safeguards are in place to mitigate confidentiality concerns

24

Page 25: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

User Experience

Page 26: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

UX Building Blocks

26

Consistent visual cue and call to action signals institutional access

Flexible and smart search • Search by institution name,

abbreviation or email• Typeahead matching and URL

Remembered institutionon next access1 2 3

Page 27: SIMPLE, TRUSTED ACCESS – ANYWHERE, ANYTIME, ON ANY … · Eduserv Elsevier Publishing Emerald Publishing Group Erasumus University Rotterdam ETHZ GEANT ... Academic Pilot report

RA21 UX Goals

27

A user only encounters a discovery process once (per browser).

The user’s institution is persisted in browser local storage and subsequently rendered in the RA21 button across all participating publishers.

1 2