24
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online resources for their users” RSA Security No magic bullet Not about technology itself

Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Embed Size (px)

Citation preview

Page 1: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Access & Identity Management

• “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online resources for their users”

RSA Security

• No magic bullet

• Not about technology itself

Page 2: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Organisational Single sign-on – the future

Local web resources

External web resources

VLE

Portal

OPAC

Database

Journals

Local authentication System

usernames & passwords

User attributesNames, email, role

Directory

SSO

Authentication transfer protocol e.g SAML, Shibboleth, AthensDA

• Single copy of data managed centrally• accurate & reliable & secure• Users become accountable & auditable

Page 3: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Beyond IP authentication:

Federation

Service

Providers

Identity Providers

Athens Resources

Registry

Athens agents

AthensDAShib

SAML

Institutional Directory

InstitutionalData source

Bulk Upload

Self registration

IP ResourcesProxies

• Individual recognition from day one• Patron attribution•Comprehensive statistics• 300 premium content vendors• user management tools designed for librarians

Page 4: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

AthensAgent

Resource

First Access

Athens Authentication Point

Athens Authority Server

Create SSOsession

Long Term Token

Session Token

User signs on with Athens orlocalauthentication

Check session token. Get attributes.

Session token

HTTP refer for authentication

Session token

Athens

Cookie

CookieLong Term Token

12

4

3

56

7

8

9

Athens Single Sign-on

Page 5: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Millions of usersWorldwide

Page 6: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

2000+ institutions

Page 7: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Single Sign-on(SSO)

Page 8: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

IdentityManagement

Page 9: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

User Provisioning

Page 10: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

ManagementInformation

- usage statistics- audit

Page 11: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Integrates with- Shibboleth- EZproxy- Active Directory- etc

Page 12: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

StandardsPolicies

AttributesEduPerson

Page 13: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Case Study 1

Page 14: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 15: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 16: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Individual Patron id’s – usable anywhere

• using the student no as patron id

• Uploaded automatically from student registry

• No personal data to allay privacy concerns

• Staff registered manually

• Next step– Integration with Campus Directory

Page 17: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Tamera Hanken says

• I chose this service because I needed something that would be reliable, easy and quick to implement, and cost effective in terms of equipment and my time.

• With this method we had to do nothing to enable our network system to use Athens. 

• Based on how easy it was to begin using, how reliable it is, students didn’t find it cumbersome or confusing—we decided to purchase

• Customer service has been friendly and prompt

Page 18: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Case Study 2

Page 19: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 20: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 21: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 22: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 23: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online
Page 24: Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online

Tailored self registration

• Library promotes URL of self registration form

• Organisational defined info– Campus, role, faculty – whatever

• Request validated by librarian or IP address

• Statistics by any defined category

• Account usable anywhere