Course Description

Privacy and Identity Management


Information and Communication Technologies, second-level study programme


doc. dr. Tomaž Klobučar


New personalized services and next generation networks, such as pervasive networks, present new threats to privacy sensitive personal data. The goal of this course is to provide a broad overview of the technologies, services, applications and procedures for privacy protection.

The students will gain theoretical and practical knowledge about privacy protection related measures, e.g. privacy legislation, privacy-enhancing technologies on the user side, on the service provider side and at communication level, or identity management systems.

Gained knowledge will enable the students to use and develop privacy protection measures. The students will be able to analyze an information system with respect to personal data protection, evaluate privacy threats, select appropriate privacy-enhancing measures and implement them. When developing their own information applications and solutions the knowledge will enable the students to meet the privacy requirements imposed by environment, legislation and standards. The students will also be able to continue research and development work in the area of privacy protection and identity management.


basic definitions (privacy, personal data, identity, anonymity, pseudonym, virtual identity etc.), privacy threats and risks, basic privacy principles

Privacy regulation and legislation:
directives 95/46/EC, 2002/58/EC and eIDAS, Slovene legislation

Privacy-enhancing technologies:
- on the user side: identity protectors, anonymous credentials, privacy preference languages, privacy negotiation protocols
- on the service provider side: organisational and monitoring processes, privacy policies, data repositories, data anonymisation.
- at communication level: anonymous communication systems (Mix networks, Onion routing, Crowds, Freenet), remailers (e.g. Mixmaster, Mixminion), anonymising web proxies, blind signature

Identity management:
basics, scenarios, requirements, mechanisms

Identity management systems:
Shibboleth, OpenID, Liberty Alliance

Course literature:

Selected chapters from the following books:

Selected papers from scientific journals, such as Computers & Security, Network Security, Journal of Computer Security

Significant publications and references:

Seminar work with oral defense (50%)
Oral or written exam (50%)

Students obligations:

Seminar work and oral defense of seminar work.