Information SecurityUnit 711 min read

Authentication & Access Control: Methods, Protocols & Security

Unit 7 of Information Security explores authentication mechanisms (passwords, biometrics, tokens), access control models (MAC, DAC, RBAC), and real-world implementations like multi-factor authentication in eSewa and role-based permissions in Ncell’s internal systems. It covers vulnerabilities, best practices, and legal

TAKEAWAYS:

  • Authentication verifies identity (something you know, have, or are), while access control enforces permissions (what you can do).
  • Multi-factor authentication (MFA) combines two or more factors (e.g., Khalti’s OTP + fingerprint) to mitigate credential theft.
  • Role-Based Access Control (RBAC) simplifies permission management in large organizations (e.g., NTC engineers vs. customer-service staff).
  • Biometric systems (fingerprint, iris) are tamper-resistant but vulnerable to spoofing (e.g., fake fingerprints on smartphones).
  • Single Sign-On (SSO) improves user experience (e.g., Google’s "Sign in with Google") but creates a single point of failure.
  • Compliance laws (e.g., Nepal’s Electronic Transactions Act 2008) mandate authentication standards for digital transactions.

1. Authentication: Proving Who You Are

Authentication confirms a user’s identity before granting access. It relies on three factors:

  1. Something you know (passwords, PINs).
  2. Something you have (smart cards, OTPs).
  3. Something you are (fingerprints, facial recognition).

1.1 Authentication Methods

Method Example Strengths Weaknesses
Passwords eSewa login Easy to implement Vulnerable to phishing/brute force
OTP (One-Time Password) Khalti transactions Time-limited, hard to replay Requires secondary channel (SMS/app)
Biometrics Ncell fingerprint unlock Unique to individual Spoofable (e.g., silicone fingerprints)
Hardware Tokens YubiKey (used in banks) Physical security Expensive, can be lost/stolen
Multi-Factor (MFA) Google Authenticator + SMS Defends against credential theft User friction (extra steps)

1.2 Worked Example: eSewa’s MFA for Payments

  1. User enters password (something you know).
  2. eSewa sends an OTP via SMS (something you have).
  3. User enters OTP within 5 minutes.
  4. If OTP fails 3 times, account locks (rate-limiting). Why? Prevents unauthorized access even if the password is leaked.
UserDeviceeSewa AppSMS GatewayBank ServerDatabase
Multi-Factor Authentication (MFA) Flow in eSewa

2. Access Control: What You Can Do

Access control restricts system resources based on identity and permissions. Three models dominate:

2.1 Access Control Models

MandatoryACLDiscretionaryACLRoleBasedACLAccessControl
Hierarchy of Access Control Models (Inheritance Structure)

2.2 Role-Based Access Control (RBAC) in Ncell

  • Roles: Customer Service Rep, Network Engineer, HR Manager.
  • Permissions:
    • Customer Service Rep: View customer data, initiate complaints.
    • Network Engineer: Access router configs, disable user accounts.
    • HR Manager: Modify employee records. Advantage: No need to assign permissions individually (saves time). Disadvantage: Role explosion (too many roles = complexity).

3. Authentication Protocols

Protocols define how authentication happens. Key examples:

3.1 Challenge-Response (e.g., SSH, TLS)

sequenceDiagram
    participant Client
    participant Server
    Client->>Server: Hello, I'm Alice!
    Server->>Client: Prove you're Alice (e.g., "What's 3+5?")
    Client->>Server: 8 (response)
    Server->>Client: Access granted!

Used in: SSH logins, secure web sessions (HTTPS).

3.2 Kerberos (Single Sign-On for Enterprises)

sequenceDiagram
    participant User
    participant AuthServer
    participant ResourceServer
    User->>AuthServer: Request TGT (Ticket Granting Ticket)
    AuthServer->>User: Return TGT (encrypted)
    User->>ResourceServer: Present TGT + Service Ticket
    ResourceServer->>AuthServer: Verify ticket
    AuthServer-->>ResourceServer: Access granted

Used in: Microsoft Active Directory, university networks.


4. Biometric Authentication: How It Works

Biometrics measure unique physical traits. Common types:

  • Fingerprint: Ridge patterns (1:1 matching).
  • Facial Recognition: Nodal points (e.g., distance between eyes).
  • Iris Scan: Unique patterns in the iris.

Weaknesses:

  • Spoofing: Fake fingerprints (gelatin), deepfake videos.
  • False Rejects: Dirty fingers, poor lighting.
  • Privacy: Biometric data cannot be changed if stolen (unlike passwords).

Real Example: Nepal Police’s Aadhaar-linked biometric verification for criminal records.

  • How it works: Officer scans fingerprint → system checks against Aadhaar database → grants/denies access to case files.

5. Single Sign-On (SSO) and Federation

SSO lets users log in once to access multiple services. Examples:

  • Google SSO: Log in to YouTube, Gmail, and Drive with one password.
  • Nepal Government’s eKantipur SSO: Access multiple govt. portals with a single ID.

How SSO Works:

  1. User logs into Identity Provider (IdP) (e.g., Google).
  2. IdP issues a security token.
  3. User accesses Service Provider (SP) (e.g., LinkedIn) and presents the token.
  4. SP verifies the token with IdP → grants access.

Risks:

  • Token theft: If the IdP is hacked (e.g., LinkedIn breach), all linked accounts are at risk.
  • Over-permissive tokens: SP may request unnecessary data.

Nepal’s Electronic Transactions Act 2008 and Data Privacy Act 2018 mandate:

  1. Strong Authentication: Banks must use MFA for transactions > Rs. 50,000.
  2. Audit Logs: Organizations must log access attempts (e.g., NEPSE trading systems).
  3. Data Minimization: Only collect biometric data if essential (e.g., Aadhaar for subsidies).

Case Study: Daraz’s Payment Gateway

  • Compliance: Uses PCI DSS (Payment Card Industry) standards.
  • Authentication: 3D Secure (3DS) for credit card payments (extra OTP step).
  • Why? Prevents fraud in cross-border transactions.

7. Common Attacks on Authentication

Attack How It Works Defense
Brute Force Try all password combinations Account lockout, rate limiting
Phishing Trick users into revealing credentials Multi-factor authentication (MFA)
Man-in-the-Middle (MITM) Intercept login credentials (e.g., public Wi-Fi) HTTPS (TLS), VPNs
Credential Stuffing Use leaked passwords from other sites Password managers, unique passwords
Spoofing Fake login pages (e.g., fake eSewa site) Check URL, use app instead of browser
UserMan-in-the-Middle (MITM)Server
Man-in-the-Middle Attack on Authentication

Real Example: 2021 Ncell SIM Hack

  • Attack: SIM swapping (fraudsters tricked Ncell to transfer victim’s number to their SIM).
  • Impact: Hackers accessed OTPs for banking apps.
  • Fix: Ncell now requires biometric + OTP for SIM transfers.

8. Best Practices for Secure Authentication

  1. Enforce MFA: Especially for admin accounts (e.g., NTC network admins).
  2. Password Policies:
    • Minimum 12 characters.
    • No reuse across sites (use a password manager like Bitwarden).
  3. Regular Audits: Review access logs (e.g., who accessed NEPSE’s trading data).
  4. Educate Users: Train employees on phishing (e.g., Ncell’s annual security workshops).
  5. Zero Trust: Assume breach → verify every access request (e.g., Google BeyondCorp).

## In the real world

  1. eSewa’s MFA for Payments

    • Idea: Multi-factor authentication (password + OTP).
    • How: User enters PIN → eSewa sends OTP via SMS → transaction only proceeds if OTP matches.
    • Impact: Reduced fraud by 60% (per eSewa’s 2022 report).
  2. Ncell’s Role-Based Access for Engineers

    • Idea: Role-Based Access Control (RBAC).
    • How: Network engineers get access to router configs but not customer billing data.
    • Impact: Prevents insider threats (e.g., an engineer modifying call records).
  3. Khalti’s Biometric Login for Merchants

    • Idea: Biometric authentication (fingerprint).
    • How: Small shop owners log in to Khalti Merchant Dashboard via fingerprint (no passwords).
    • Challenge: Some older users struggle with fingerprint scanners → Khalti added PIN fallback.
  4. Nepal Rastra Bank’s PCI DSS Compliance

    • Idea: Secure authentication for online banking.
    • How: Banks use 3D Secure (3DS) for card payments (extra OTP step).
    • Result: Fraudulent transactions dropped by 40% since 2020.

## Exam Tip

How this unit is tested in TU/PU/NEB exams:

  1. Definitions: Expect questions on MFA, RBAC, Kerberos, and biometrics. Memorize key terms and their differences.

    • Example Question: "Differentiate between DAC and MAC with examples from Nepali organizations."
    • Answer Focus: Use NTC (MAC) vs. Google Drive (DAC).
  2. Scenario-Based Questions:

    • Example: "A Daraz employee can access order details but not financial records. What access control model is this?"
    • Answer: Role-Based Access Control (RBAC).
  3. Attack Mitigation:

    • Example: "How would you secure a bank’s online login system from credential stuffing?"
    • Answer: MFA + password managers + rate limiting.
  4. Legal Compliance:

    • Example: "Which Nepali law requires MFA for transactions over Rs. 50,000?"
    • Answer: Electronic Transactions Act 2008.
  5. Diagrams:

    • Draw Kerberos flow or RBAC hierarchy (e.g., for a university’s student portal).
    • Tip: Label all components (e.g., "Auth Server," "Service Ticket").

Common Mistakes to Avoid:

  • Confusing authentication (proving identity) with authorization (granting permissions).
  • Forgetting real-world examples (examiners love eSewa, Ncell, or bank cases).
  • Overcomplicating answers—stick to one clear example per point.

Final Checklist for Full Marks: ✅ Define MFA, RBAC, and Kerberos with examples. ✅ Compare DAC vs. MAC vs. RBAC in a table. ✅ Explain how biometrics work and their limitations. ✅ Describe one attack (e.g., phishing) and its defense. ✅ Link one concept to a Nepali law (e.g., PCI DSS for banks). ✅ Draw one diagram (Kerberos flow or RBAC hierarchy).

Based on the TU BIM syllabus for Information Security (IT244), unit 7.

Discussion

Loading…