Details zu Semesterangebot Methods of User Authentication in WS 2025/26 im Studiengang Informatik - Master
| Name (deutsch) | Methods of User Authentication |
| Name (englisch) | Methods of User Authentication |
| andere Einordnungen |
INFMSc25 - INF - IT-Sicherheit (ITSEC) TIMSc25 - INF - IT-Sicherheit (ITSEC) |
| Semesterangebot | Lehrveranstaltung und Prüfung |
| Kompetenzbereich | Informatik [INF MSC] - Pflicht (im Studiengang) - |
| Modulgruppe | IT-Sicherheit (ITSEC) - Wahlpflicht (im Kompetenzbereich) - |
| Semesterwochenstunden (SWS) | 2V |
| Leistungspunkte (LP) | 3 LP |
| mögliche Prüfungsleistungen | Klausur (K) |
| Prüfungsleistung in diesem Semester | Klausur (K) |
| Prüfungsdauer |
60 |
| Webseite | https://group.cispa.io/golla/teaching.html |
| Vorkenntnisse |
Prior knowledge from the lecture 'Grundlagen der IT-Sicherheit' is required. Additionally, knowledge from the courses 'Einführung Usable Security und Privacy' and 'Kryptographie' is recommended. |
| Qualifikationsziele |
Students gain an in-depth understanding of security and usability challenges in user authentication. They are familiar with core concepts from cryptography, protocol design, usability engineering, and Web standardization. Students are able to critically analyze real-world authentication schemes and assess their security, usability, and deployability. By the end of the course, students can advocate for and apply modern, user-centered authentication methods grounded in empirical findings and sound security principles. |
| Literatur |
Will be announced during the course. |
| Inhalt und Stoffplan |
The lecture begins by differentiating authentication from authorization before examining password-based authentication, its weaknesses, and reinforcement strategies, including hashing, strength metrics, and common attacks like credential stuffing and phishing. It then covers defenses such as password managers, two-factor authentication, risk-based authentication, breach alerts, and security warnings. Students will also explore PAKEs, challenge-response protocols, biases in graphical passwords, and mobile authentication security (e.g., PINs). The course concludes with analyzing password alternatives like biometrics and hardware tokens, leading to an in-depth evaluation of modern passwordless authentication, such as passkeys, and the security-usability trade-offs in authentication design. Please note that some topics listed below will take more than one lecture session:1. Introduction: Overview, Definitions, UDS Criteria2. Knowledge-Based Authentication- PINs and Passwords- Hashing, Guessing, Strength Metrics- Attacks and Threat Models- Authentication Protocols (PAKEs, SSO)- Reinforcement (MFA, RBA, and Warnings)- Password Managers- Fallback Authentication- Graphical Passwords3. Biometry-Based Authentication- Face and Fingerprint Recognition- Behavioral Biometrics, Multimodal Systems, Privacy Aspects4. Token-Based Authentication- Hardware Security Keys, Smartcards, and Phones- Passwordless Authentication (Passkeys and FIDO)5. Misc- Implicit and Continuous Authentication- Evaluation of Authentication Schemes- Accessibility- Case Studies |
| Sprache |
englisch |
| Prüfungsanmeldung |
Zeitraum für alle Prüfungsformen außer VbP |
| Weitere Angaben und Bemerkungen |
Lehrauftrag von Dr. Maximilian Golla vom CISPA.
|
| Gültigkeit | ab WS 2025/26 |
| Rolle | Person | WWW | Institut / Organisationseinheit | |
|---|---|---|---|---|
| Prüfer:in | Dr. Maximilian Golla | fahl@sec.uni-hannover.de | https://www.sec.uni-hannover.de/ | Fachgebiet Empirical Information Security |
| Dozent:in | Dr. Maximilian Golla | fahl@sec.uni-hannover.de | https://www.sec.uni-hannover.de/ | Fachgebiet Empirical Information Security |