Paper accepted at ACNS 2025

Our paper entitled “Continuous Authentication Beyond Error Rates: Reviewing General System Properties” by Florian Dehling, Sebastian Kawelke, and Luigi Lo Iacono, has been accepted at ACNS 2025. The paper presents a systematic analysis of so-far proposed systems for continuous authentication. The analysis focuses on fundamental system properties, such as attacker models or deployment schemes, and highlights research and development needs.

Paper accepted at TrustCom 2024

Our paper entitled “You Are as You Type: Investigating the Influence of Timestamp Accuracy on the Robustness of Keystroke Biometrics” by Florian Dehling, Sebastian Koch, Luigi Lo Iacono and Hannes Federrath, has been accepted at TrustCom 2024. In the paper, we present the results of a study that examines how limiting the precision of time stamps affects the performance of algorithms for analysing typing behaviour, which can be used for continuous authentication systems as well as for tracking users.

Next stop: Giessen.

Following the promotion of our group leader, Luigi Lo Iacono, to the position of professor of IT security at Justus Liebig University Giessen, the ‘Data and Application Security’ group is also changing location. The updated contact information can be found under Members.

Mehrere Beiträge aus D'accord im DuD-Schwerpunktheft Datenschutz trifft Datenökonomie

In der Ausgabe 2/2024 widmet sich die Zeitschrift DuD Datenschutz und Datensicherheit dem Schwerpunktthema Datenschutz und Datenökonomie. Die Beiträge geben einen Überblick über aktuelle Arbeiten zum Thema Datenschutz im Kontext der Plattformökonomie – von der Erfassung des aktuellen Ist-Zustandes und Einführung in das Problemfeld, über die Analyse und Bewertung der Rahmenbedingungen, bis hin zu den Wegen für eine effektive praktische Umsetzung von gebrauchstauglichen Datenschutzfunktionen.

Die Gruppe für Daten- und Anwendungssicherheit war an den folgenden Beiträgen beteiligt:

Eine Übersicht aller Beiträge finden Sie auf dem Internetauftritt des D’accord Projekts.

Master Thesis on EAP-TLS implementation and security in 5G systems accepted for the 20th German IT Security Congress

The master thesis entitled “Enabling EAP-TLS as authentication mechanism over non-3GPP access for private 5G networks” by Julius Röttger has been accepted for the 20th German IT Security Congress.

The master thesis involves the creation and execution of a prototype incorporating EAP-TLS within a 5G-Core, with subsequent evaluation using a non-3GPP access in a built testbed. The assessment includes various attacks and Key Performance Indicator (KPI) measurements, providing initial insights into both the implementation and security aspects of EAP-TLS within a 5G system.

Paper on users' perceptions of privacy in continuous authentication accepted for PETS 2024

Our paper entitled “Internet Users’ Willingness to Disclose Biometric Data for Continuous Online Account Protection: An Empirical Investigation” by Florian Dehling, Jan Tolsdorf, Hannes Federrath, and Luigi Lo Iacono has been accepted for the 24th Privacy Enhancing Technologies Symposium (PETS 2024).

The paper reports on a study with 830 participants from the U.S., aiming to investigate user perceptions towards continuous authentication across different classes of online services. The results provide valuable insights on human factors for the design and implementation of privacy conscious continuous authentication systems in practice.

Two book chapters published in Human Factors in Privacy Research (Open Access)

Two chapters (co-)authored by members of our research group have been published in the open access book Human Factors in Privacy Research.

The chapter titled Achieving Usable Security and Privacy Through Human-Centered Design, co-authored by Jan Tolsdorf, Stephan Wiefling, and Luigi Lo Iacono, discusses practical methods to create usable security and privacy solutions using the human-centered design process.

The chapter titled Data Cart: A Privacy Pattern for Personal Data Management in Organizations by Jan Tolsdorf and Luigi Lo Iacono introduces a privacy pattern called Data Cart, developed through a user-centered approach. The pattern assists in creating tailored technical and organizational data protection measures that align with employees’ requirements, ultimately enhancing privacy compliance.

David Langer successfully defended his dissertation

David Langer successfully defended his dissertation entitled “The Structuration of Moral Capital and Unethical Behavior: When the Organization Hits an Ethical Meltdown” in Wuppertal on 12 July 2023. David has successfully completed the PhD Programme of the Schumpeter School of Business and Economics at the Bergische Universität Wuppertal. Congratulations!

Stephan Wiefling successfully defended his dissertation

Stephan Wiefling successfully defended his dissertation entitled “Usability, Security, and Privacy of Risk-Based Authentication” in Bochum on 08 May 2023. His dissertation project was carried out as part of a collaboration between the DAS-Group of Prof. Luigi Lo Iacono at H-BRS and the Usable Security and Privacy research group of Prof. Markus Dürmuth. Stephan has successfully completed the PhD Programme of the Faculty of Computer Science at the Ruhr-University Bochum. Congratulations!

Jan Tolsdorf gives a talk at the Stammtisch of the Cyber Security Cluster Bonn

Jan Tolsdorf will give an invited talk (in German) on our ongoing research project MedISA. In the project, a catalog of measures for increasing information security awareness is being developed specifically for medical care facilities. The presentation will introduce the project in more detail, present initial research results, and provide an outlook on future work.

Date and time: February 28, 2023 at 4pm - 5:30 pm

Further information and registration can be found here.