Authentication and A Guide - Resources and Review

A collection of documents from a project which is working to provide a certificate / public key infrastructure that will meet authentication needs of all the campuses of the University of Califronia.
 
Study undertaken to identify the real, business
led requirements for information security within UK HE, and to recommend solutions or approaches to address those requirements. The findings from the study confirmed the need for institutions to adopt a more substantial information security position and identified security issues covering both management and technical solutions.
 
Article offering explanations of key concepts, details on using Sun's Java Web Server to press digital certificates for use with Netscape Web browsers, and a discussion of progress required to develop digital certificates which could manage computer access effectively. The content of a digital certificate is covered, along with issuing policies.
 
Study of the technologies available to support authentication, reviews the needs expressed by a set of people contacted for the study, and provides the beginnings of a road
map on how a national system might be established.
 
Presents the findings of a consultation exercise to understand the nature and scope of the security requirements within UK higher education.
 
System developed by NISS to enable controlled access to subscription services.
 
Provides recommendations on how JISC might act to improve the security of UK HE networking. Suggests seven necessary actions including, facilitating the development of a support infrastructure for local IT management, encouraging and supporting institutions in the development of network security strategies and defining a common framework for local access schemes.
 
Refereed article discussing the use of identity authentication systems in the conduct of electronic commerce. Investigates the variety of identity authentication systems available, and argues that this area is in particular need of further research.
 
Article providing information on key issues including problems with usernames, passwords and IP address filtering, single sign
on, privacy, usage and statistics. Benefits and drawbacks of the Athens system of authentication are discussed.
 
Discussion of the issues attached to the implementation of the ATHENS access management system. Points out that the lessons from ATHENS could suggest that success will only be achieved if at least equal attention is paid to the needs of those who will have to manage the final system as to the technical detail.
 
Proceedings of the Ninth Australasian Information Online and On Disc Conference and Exhibition, held in Sydney Australia, January 1999. Many of the papers reflect the challenges of managing information. Issues include access and rights, sustaining sites, improving access via gateways, verification and authentication, search engines and directories, integration with existing library information systems, and using the technology of the Internet in tasks such as serving remote library users.
 
Document released in April 1998 which aims to identify current issues in authentication and to provide a framework for analyzing them, to map out the various best
practice approaches to solving these problems using existing and emerging technology, to provide a common vocabulary and framework to assist in the development of licensing and resource-sharing agreements, and to highlight technical and policy considerations that need to be addressed as part of these business negotiations.
 
Article which examines four alternative solutions to the problems and requirements of authentication of access to networked information resources: Mechanical Proxies, Application Proxies, Credential Based approaches, and a Proxy/Credential Hybrid. It concludes that campuses must establish authentication schemes, and that successful schemes will be able to mask their complexity from users.
 
Report covering issues such as authentication, authorisation, privacy and cryptography on the Web, as well as Netscape's Secure Socket Layer (SSL) and Pretty Good Privacy (PGP).
 
Full text of presentations about some of the issues surrounding authentication, including the Athens authentication system and its implications for electronic or hybrid libraries, as well as alternative and international approaches.
 
Article describing username and password problems for computer users and support staff, caused by the growth of networked dataset providers. Problems are discussed in relation to security and interworking between authentication domains.
 
Nb = 16