Sie haben diese Webseite über eine veraltete URL aufgerufen. Die URL https://modkat.dbs.uni-hannover.de wird in Zukunft abgeschaltet.
Der Modulkatalog ist ab sofort unter https://modkat.fei.uni-hannover.de erreichbar.

Details zu Semesterangebot Methods of User Authentication in WS 2025/26 im Studiengang Informatik - Master

Name (deutsch)Methods of User Authentication
Name (englisch)Methods of User Authentication
andere Einordnungen INFMSc25 - INF - IT-Sicherheit (ITSEC)
TIMSc25 - INF - IT-Sicherheit (ITSEC)
SemesterangebotLehrveranstaltung und Prüfung
KompetenzbereichInformatik [INF MSC]
- Pflicht (im Studiengang) -
ModulgruppeIT-Sicherheit (ITSEC)
- Wahlpflicht (im Kompetenzbereich) -
Semesterwochenstunden (SWS)2V
Leistungspunkte (LP)3 LP
mögliche PrüfungsleistungenKlausur (K)
Prüfungsleistung in diesem SemesterKlausur (K)
Prüfungsdauer

60

Webseite https://group.cispa.io/golla/teaching.html
Vorkenntnisse

Prior knowledge from the lecture 'Grundlagen der IT-Sicherheit' is required. Additionally, knowledge from the courses 'Einführung Usable Security und Privacy' and 'Kryptographie' is recommended.

Qualifikationsziele

Students gain an in-depth understanding of security and usability challenges in user authentication. They are familiar with core concepts from cryptography, protocol design, usability engineering, and Web standardization. Students are able to critically analyze real-world authentication schemes and assess their security, usability, and deployability. By the end of the course, students can advocate for and apply modern, user-centered authentication methods grounded in empirical findings and sound security principles.

Literatur

Will be announced during the course.

Inhalt und Stoffplan

The lecture begins by differentiating authentication from authorization before examining password-based authentication, its weaknesses, and reinforcement strategies, including hashing, strength metrics, and common attacks like credential stuffing and phishing. It then covers defenses such as password managers, two-factor authentication, risk-based authentication, breach alerts, and security warnings. Students will also explore PAKEs, challenge-response protocols, biases in graphical passwords, and mobile authentication security (e.g., PINs). The course concludes with analyzing password alternatives like biometrics and hardware tokens, leading to an in-depth evaluation of modern passwordless authentication, such as passkeys, and the security-usability trade-offs in authentication design. Please note that some topics listed below will take more than one lecture session:1. Introduction: Overview, Definitions, UDS Criteria2. Knowledge-Based Authentication- PINs and Passwords- Hashing, Guessing, Strength Metrics- Attacks and Threat Models- Authentication Protocols (PAKEs, SSO)- Reinforcement (MFA, RBA, and Warnings)- Password Managers- Fallback Authentication- Graphical Passwords3. Biometry-Based Authentication- Face and Fingerprint Recognition- Behavioral Biometrics, Multimodal Systems, Privacy Aspects4. Token-Based Authentication- Hardware Security Keys, Smartcards, and Phones- Passwordless Authentication (Passkeys and FIDO)5. Misc- Implicit and Continuous Authentication- Evaluation of Authentication Schemes- Accessibility- Case Studies

Sprache

englisch

Prüfungsanmeldung

Zeitraum für alle Prüfungsformen außer VbP

Weitere Angaben und Bemerkungen
Lehrauftrag von Dr. Maximilian Golla vom CISPA.
Gültigkeit ab WS 2025/26


RollePersonE-MailWWWInstitut / Organisationseinheit
Prüfer:in Dr. Maximilian Golla fahl@sec.uni-hannover.de https://www.sec.uni-hannover.de/ Fachgebiet Empirical Information Security
Dozent:in Dr. Maximilian Golla fahl@sec.uni-hannover.de https://www.sec.uni-hannover.de/ Fachgebiet Empirical Information Security