NISO RP-11-2011 ESPReSSO Establishing Suggested Practices Regarding Single Sign-On《ESPReSSO 就单个开始指令建立建议操作》.pdf
《NISO RP-11-2011 ESPReSSO Establishing Suggested Practices Regarding Single Sign-On《ESPReSSO 就单个开始指令建立建议操作》.pdf》由会员分享,可在线阅读,更多相关《NISO RP-11-2011 ESPReSSO Establishing Suggested Practices Regarding Single Sign-On《ESPReSSO 就单个开始指令建立建议操作》.pdf(43页珍藏版)》请在麦多课文档分享上搜索。
1、 NISO RP-11-2011 ESPReSSO: Establishing Suggested Practices Regarding Single Sign-On A Recommended Practice of the National Information Standards Organization Abstract: ESPReSSO explores practical solutions for improving the success of SSO authentication technologies for providing a seamless experie
2、nce for the user and makes recommendations for promoting the adoption of one or more of these solutions to make the access improvements a reality. Published by: NISO, Baltimore, Maryland, U.S.A. Approved: October 25, 2011NISO RP-11-2011 ESPReSSO ii 2011 NISO About NISO Recommended Practices A NISO R
3、ecommended Practice is a recommended “best practice” or guideline for methods, materials, or practices in order to give guidance to the user. Such documents usually represent a leading edge, exceptional model, or proven industry practice. All elements of Recommended Practices are discretionary and m
4、ay be used as stated or modified by the user to meet specific needs. This recommended practice may be revised or withdrawn at any time. For current information on the status of this publication contact the NISO office or visit the NISO website (www.niso.org). Published by National Information Standa
5、rds Organization (NISO) One North Charles Street, Suite 1905 Baltimore, MD 21201 www.niso.org Copyright 2011 by the National Information Standards Organization All rights reserved under International and Pan-American Copyright Conventions. For noncommercial purposes only, this publication may be rep
6、roduced or transmitted in any form or by any means without prior permission in writing from the publisher, provided it is reproduced accurately, the source of the material is identified, and the NISO copyright status is acknowledged. For permission to photocopy or use material electronically from NI
7、SO RP-11-2011, ESPReSSO: Establishing Suggested Practices Regarding Single Sign-On, please access or contact the Copyright Clearance Center, Inc. (CCC) at 222 Rosewood Drive, Danvers, MA 01923, 978-750-8400. CCC is a not-for-profit organization that provides licenses and registration for a variety
8、of users. All inquiries regarding translations into other languages or commercial reproduction or distribution should be addressed to: NISO, One North Charles Street, Suite 1905, Baltimore, MD 21201. ISBN (13): 978-1-880124-98-7 ESPReSSO NISO RP-11-2011 2011 NISO iii Table of Contents Foreword . v P
9、art 1: Introduction . 1 1.1 Purpose and Scope 1 1.2 Terms and Definitions . 1 Part 2: Why Is It Time to Act? 4 2.1 Overview of Issues 4 2.2 Library Community. 4 2.4 End User Community 5 Part 3: Traditional Approaches to Controlling Access to Licensed Resources 6 3.1 The Evolution of Authentication R
10、equirements 6 3.2 The Evolution of Access Control 7 3.2.1 Client Machine IP Address and Client Organization VPN Services 7 3.2.2 Proxy Servers . 9 3.2.3 Userids/Passwords for a Service Provider Site . 10 3.2.4 Federated Login (Authentication). 11 Part 4: ESPReSSO Recommendations . 16 4.1 Overview .
11、16 4.2 Use Cases 17 4.3 Summary of Recommendations 18 4.4 Recommendations to Service Providers 21 4.4.1 Service Provider Open Page . 21 4.4.2 Service Provider Identity Discovery Page 21 4.4.3 Service Provider Protected Page. 23 4.4.4 Attribute-Based Authorization . 24 4.5 Recommendations to Librarie
12、s / Institutions. 24 4.5.1 Institution Login Page 24 4.5.2 Institution Menu Page. 25 4.6 Role of a Proxy Server in Supporting a Hybrid Environment . 27 4.7 Rewriting OpenURLs . 27 4.8 Appropriate Use of Branding 27 4.9 Additional Functionality . 28 4.9.1 Pseudonymous Access 28 4.9.2 User Consent to
13、Attribute Release 29 Part 5: Content Discovery Services . 30 5.1 Content Discovery Services 30 5.1.1 Overview of Federated Search . 30 5.1.2 Overview of Web-Scale Discovery Services 31 5.2 Existing Authentication with Discovery Services . 32 5.3 Recommendations for Authentication in a Discovery Sear
14、ch Environment . 32 Appendix A Description of Functions in Current Authentication Environments . 33 Bibliography 35 NISO RP-11-2011 ESPReSSO iv 2011 NISO Figures Figure 1: Use case #1 scenario . 17 Figure 2: Use case #2 scenario . 17 Figure 3: Use case #3 scenario . 17 Figure 4: Use case #4 scenario
15、 . 18 Figure 5: Mock-up of Identity Discovery page using recommendations 23 Figure 6: Mock-up of Institution Login Page using recommendations 25 Figure 7: Example of Institution Menu Page 26 Figure 8: Federated search 30 Figure 9: Web-scale discovery search 31 Figure 10: Functional components of cur
16、rent authentication environments . 33 ESPReSSO NISO RP-11-2011 2011 NISO v Foreword About This Recommended Practice In 2009, NISO launched a new Chairs Initiativea project of the chair of NISOs Board of Directors, focusing on a specific issue that would benefit from study and the development of a re
17、commended practice or standard. Oliver Pesch, Chair of NISOs Board of Directors at the time, chose the issue of standardizing seamless, item-level linking through single sign-on (SSO) authentication technologies in a networked information environment. Accessing information in a networked environment
18、 has been a reality for most library user communities for over a decade. Recent years have seen an explosion in this type of usage. With the advent of hosted, aggregated full-text databases and the proliferation of e-journals and e-books, users searches for information often take them to a number of
19、 different online hosts and platforms as part of a single transaction. When those information resources are commercial products, each platform traditionally required the user to be authenticated and authorized. Service providers (SPs) have used two approaches to this issue: 1) ensuring that the requ
20、esting IP address is within a range assigned to the license holder, and 2) issuing userids and passwords to users. In the latter case, the user may have a different identity on each platform. As usage habits and technology have evolved, these traditional methods no longer work well. With the growing
21、 complexity of licensing situations and network design, along with the increased usage from mobile devices, campuses have outgrown the capabilities of these approaches. Using and managing this environment has become confusing and error-prone for browser users, licensee organizations, and service pro
22、viders. The problems caused by having to manage multiple identities have led to the development of so-called “Single Sign-On” (SSO) authentication technologies, including proprietary technologies such as Athens and formal open standards such as SAML (security assertion markup language). With these t
23、echnologies, the user authenticates once and can then access all compliant content platforms using the same identity. (The user would typically be authenticated by the organization holding the licenses.) More importantly, these technologies have been designed so the user would encounter only one log
24、in event while traversing a multitude of in-sourced and outsourced service providers. In addition, with the SSO technologies the user does not have to be using a device attached to the license holders network; they can be anywhere in the world. Simplifying the user experience has become more importa
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- NISORP112011ESPRESSOESTABLISHINGSUGGESTEDPRACTICESREGARDINGSINGLESIGNONESPRESSO 单个 开始 指令 建立 建议 操作 PDF

链接地址:http://www.mydoc123.com/p-1008896.html