Planning
Technology
About Converia

Shibboleth at academic conferences: Log in using your university credentials

Registering for a conference online almost always requires creating a user account first. Given the sheer number of passwords we are already asked for in our daily lives, hardly anyone is happy about having to come up with yet another one. Fortunately, this is no longer necessary for scientific conferences—thanks to Shibboleth.

Those who have to remember many login details either write down usernames and passwords on a list (only to lose the piece of paper eventually), use the same password for everything (leaving the door wide open for hackers), or manage everything with a password manager. The latter is a good solution, but many people still find it difficult to set up, meaning these users remain a rare species. This is confirmed by the access data analyzed by the startup Identeco for the University of Bonn: "123456," "password," or "abc123" still occupy top spots on the list of the most popular passwords. The 67 million data points examined are the spoils of numerous data leaks, the victims of which clearly do not seem to follow any personal password strategy.

This can also be risky for conference participants. Personal data is stored in the conference account—not necessarily information that should be openly accessible to others.

Reusable accounts

Users are increasingly encountering a button during mandatory registration for programs and services that offers the option to log in using an existing account from another provider, such as their Google, Facebook, or Apple account. This allows people to log into an application without having to create a new user account and password first.

Shibboleth bei wissenschaftlichen Konferenzen - Mit eigenem Account einloggen
Users have a choice: either register as a new user or log in with their own Google or Apple account

Such a so-called Single Sign-On (SSO)—a one-time login to use multiple applications with the same credentials—is also available for organizations in the scientific community. It is managed there through a process with the rather unusual name Shibboleth.

The explanations found during a quick Google search for Shibboleth are often a bit convoluted and remain cryptic for conference organizers without a technical background. It is understandable if someone gives up on a text peppered with terms like "distributed authentication," "localization service," and "identity repository" because it is simply too much jargon at once. On the other hand, it is a shame, because Shibboleth significantly shortens and secures the registration process for conferences. Let's try an explanation that hopefully sheds a little more light on the subject.

Simple login for scientists

Just like the "Sign in with Google" button, Shibboleth eliminates the need to create a new user account for individual applications. The prerequisite for this is that the software the user wants to use belongs to a federation. For example, our conference management software, Converia, is part of the DFN-AAI federation. This is an association of the German National Research and Education Network that connects members of scientific institutions (universities, research institutes, libraries, etc.) with web-based applications (e.g., Converia, library databases, learning platforms, university webmail).

This means that a research assistant at a university of applied sciences can use her university login to access all applications within the federation. Without Shibboleth, she would need a separate user account and password for each of these applications.

To ensure that a person belongs to a DFN-AAI institution, Shibboleth always checks the following during the first login:

  • that the user is truly the person they claim to be (authentication)
  • that the user has the rights to use the application (authorization)

Incidentally, the "AAI" in DFN-AAI stands for "Authentication and Authorization Infrastructure," which points to the upcoming verification process right in the name of the federation.

How does Shibboleth work for conference management software?

As part of the DFN-AAI federation, Converia is a Shibboleth-secured application. In Shibboleth jargon, every application is considered a Service Provider: it provides a service, in our case, conference registration.

In a concrete example, it looks like this: A university department is hosting its annual conference. Online registration and abstract submission take place via the conference website, which the organizing team created using Converia. An employee from another university now wants to attend the conference and purchase a ticket.

On the website, he first has to decide: either create a new user account in Converia or take the easier route by logging in with his university credentials.

Shibboleth bei wissenschaftlichen Konferenzen - Einloggen statt registrieren
Log in instead of registering

Because he wants to use his university account, the user clicks on the "DFN-AAI" button, thereby initiating the verification process described above:

1. Where are you from?
It starts with the service provider (Converia) directing the user to the discovery service. As mentioned earlier, the DFN-AAI federation includes many different organizations from the scientific community, including all German universities. The user must now select their university, as that is where their data is stored.

Shibboleth bei wissenschaftlichen Konferenzen - Lokalisierungsdienst
A simple task: The discovery service only needs to know which university the user belongs to

2. Who are you?
Once the discovery service learns in the first step that the user works at the University of Mainz, it redirects them to the University of Mainz. The university acts as the Identity Provider, because that is where the user's data and access rights are stored. On the website, the user finds a login area to enter their credentials. By logging in, they identify themselves as a member of JGU Mainz.

Shibboleth bei wissenschaftlichen Konferenzen - JGU Mainz
The login takes place in a secure environment – at your own university

3. Successfully logged in
Once the login is successful, the user is redirected back to the service provider, Converia. The verification of the user and their permissions is complete, and nothing stands in the way of registering for the conference.

How secure is Shibboleth?

When a user completes the verification process, Shibboleth transmits some personal data (= attributes, i.e., specific characteristics of a person) to the provider of the conference software. In the case of Converia, a personal ID, email address, and surname are transmitted – this way, Converia knows that the user belongs to a specific organization within the DFN-AAI federation. However, the full login process with the personal password is not sent to us, because Shibboleth is very sparing and transparent when it comes to transmitting personal data. The password is, of course, checked during entry, but this happens on computers belonging to the Identity Provider, not Converia. Even after that, the password does not reach us.

Every service provider is also contractually obligated to the federation to comply with all data protection regulations. If a provider cannot guarantee this, they are not admitted to the federation in the first place.

And: Shibboleth is more reliable than many VPN connections, which also ensure that an organization's internal services can be used from outside (e.g., in a home office). Depending on the location, however, a VPN connection can be unstable and lead to connection drops, which happens frequently, especially with mobile devices. Shibboleth does not have such problems. Furthermore, unlike VPN, there is no need to install special software beforehand, because Shibboleth is web-based and works independently of the device used to log in.

Does Shibboleth work with every conference management software?

To do this, the provider must first be recognized as an official service provider and be part of a federation. A directory of all members of the DFN-AAI federation can be found here. Converia is also listed in the list of service providers.

Why should Shibboleth be used for scientific conferences?

Scientists generally use many online applications and attend a conference or two every year. If not every one requires an extra user account and can be managed with the same login, it means much less effort. At the same time, people who use single sign-on are significantly more secure, because the less often a password has to be entered, the fewer opportunities there are for attackers to intercept sensitive data.

Furthermore, conference registration via Shibboleth is open to everyone who works at an organization within the federation. It does not matter where someone studies or works, as long as the institution belongs to the federation. This allows a person to register for a conference organized by a university in Munich using the login from their university in Berlin.

And: Shibboleth is open source, which is why it is free for organizations to use. The system is financed through donations and paid memberships, which are particularly useful for large institutions that use Shibboleth extensively.

Fast & secure login

Overall, the Shibboleth login for conferences is a fast and secure alternative to the standard registration process. Participants do not have to remember or write down countless passwords, and their access credentials remain secret from the service providers.

Of course, it is still possible to set up a standard Converia user account, and logging in via DFN-AAI is always just an option, not a requirement. After all, most conferences are also open to interested parties from outside the fields of science and research.

About the author

Laura Wirsing
Laura Wirsing
Converia

Are you planning a conference with a complex program?

30-minute consultation: We will review your requirements and show you what a realistic setup could look like.
Schedule a consultation
Schedule a consultation

More articles