Information SecurityUnit 711 min read
Authentication & Access Control: Methods, Protocols & Security
Unit 7 of Information Security explores authentication mechanisms (passwords, biometrics, tokens), access control models (MAC, DAC, RBAC), and real-world implementations like multi-factor authentication in eSewa and role-based permissions in Ncell’s internal systems. It covers vulnerabilities, best practices, and legal
TAKEAWAYS:
- Authentication verifies identity (something you know, have, or are), while access control enforces permissions (what you can do).
- Multi-factor authentication (MFA) combines two or more factors (e.g., Khalti’s OTP + fingerprint) to mitigate credential theft.
- Role-Based Access Control (RBAC) simplifies permission management in large organizations (e.g., NTC engineers vs. customer-service staff).
- Biometric systems (fingerprint, iris) are tamper-resistant but vulnerable to spoofing (e.g., fake fingerprints on smartphones).
- Single Sign-On (SSO) improves user experience (e.g., Google’s "Sign in with Google") but creates a single point of failure.
- Compliance laws (e.g., Nepal’s Electronic Transactions Act 2008) mandate authentication standards for digital transactions.
1. Authentication: Proving Who You Are
Authentication confirms a user’s identity before granting access. It relies on three factors:
- Something you know (passwords, PINs).
- Something you have (smart cards, OTPs).
- Something you are (fingerprints, facial recognition).
1.1 Authentication Methods
| Method | Example | Strengths | Weaknesses |
|---|---|---|---|
| Passwords | eSewa login | Easy to implement | Vulnerable to phishing/brute force |
| OTP (One-Time Password) | Khalti transactions | Time-limited, hard to replay | Requires secondary channel (SMS/app) |
| Biometrics | Ncell fingerprint unlock | Unique to individual | Spoofable (e.g., silicone fingerprints) |
| Hardware Tokens | YubiKey (used in banks) | Physical security | Expensive, can be lost/stolen |
| Multi-Factor (MFA) | Google Authenticator + SMS | Defends against credential theft | User friction (extra steps) |
1.2 Worked Example: eSewa’s MFA for Payments
- User enters password (something you know).
- eSewa sends an OTP via SMS (something you have).
- User enters OTP within 5 minutes.
- If OTP fails 3 times, account locks (rate-limiting). Why? Prevents unauthorized access even if the password is leaked.
2. Access Control: What You Can Do
Access control restricts system resources based on identity and permissions. Three models dominate:
2.1 Access Control Models
2.2 Role-Based Access Control (RBAC) in Ncell
- Roles: Customer Service Rep, Network Engineer, HR Manager.
- Permissions:
- Customer Service Rep: View customer data, initiate complaints.
- Network Engineer: Access router configs, disable user accounts.
- HR Manager: Modify employee records. Advantage: No need to assign permissions individually (saves time). Disadvantage: Role explosion (too many roles = complexity).
3. Authentication Protocols
Protocols define how authentication happens. Key examples:
3.1 Challenge-Response (e.g., SSH, TLS)
sequenceDiagram
participant Client
participant Server
Client->>Server: Hello, I'm Alice!
Server->>Client: Prove you're Alice (e.g., "What's 3+5?")
Client->>Server: 8 (response)
Server->>Client: Access granted!Used in: SSH logins, secure web sessions (HTTPS).
3.2 Kerberos (Single Sign-On for Enterprises)
sequenceDiagram
participant User
participant AuthServer
participant ResourceServer
User->>AuthServer: Request TGT (Ticket Granting Ticket)
AuthServer->>User: Return TGT (encrypted)
User->>ResourceServer: Present TGT + Service Ticket
ResourceServer->>AuthServer: Verify ticket
AuthServer-->>ResourceServer: Access grantedUsed in: Microsoft Active Directory, university networks.
4. Biometric Authentication: How It Works
Biometrics measure unique physical traits. Common types:
- Fingerprint: Ridge patterns (1:1 matching).
- Facial Recognition: Nodal points (e.g., distance between eyes).
- Iris Scan: Unique patterns in the iris.
Weaknesses:
- Spoofing: Fake fingerprints (gelatin), deepfake videos.
- False Rejects: Dirty fingers, poor lighting.
- Privacy: Biometric data cannot be changed if stolen (unlike passwords).
Real Example: Nepal Police’s Aadhaar-linked biometric verification for criminal records.
- How it works: Officer scans fingerprint → system checks against Aadhaar database → grants/denies access to case files.
5. Single Sign-On (SSO) and Federation
SSO lets users log in once to access multiple services. Examples:
- Google SSO: Log in to YouTube, Gmail, and Drive with one password.
- Nepal Government’s eKantipur SSO: Access multiple govt. portals with a single ID.
How SSO Works:
- User logs into Identity Provider (IdP) (e.g., Google).
- IdP issues a security token.
- User accesses Service Provider (SP) (e.g., LinkedIn) and presents the token.
- SP verifies the token with IdP → grants access.
Risks:
- Token theft: If the IdP is hacked (e.g., LinkedIn breach), all linked accounts are at risk.
- Over-permissive tokens: SP may request unnecessary data.
6. Legal and Compliance Aspects in Nepal
Nepal’s Electronic Transactions Act 2008 and Data Privacy Act 2018 mandate:
- Strong Authentication: Banks must use MFA for transactions > Rs. 50,000.
- Audit Logs: Organizations must log access attempts (e.g., NEPSE trading systems).
- Data Minimization: Only collect biometric data if essential (e.g., Aadhaar for subsidies).
Case Study: Daraz’s Payment Gateway
- Compliance: Uses PCI DSS (Payment Card Industry) standards.
- Authentication: 3D Secure (3DS) for credit card payments (extra OTP step).
- Why? Prevents fraud in cross-border transactions.
7. Common Attacks on Authentication
| Attack | How It Works | Defense |
|---|---|---|
| Brute Force | Try all password combinations | Account lockout, rate limiting |
| Phishing | Trick users into revealing credentials | Multi-factor authentication (MFA) |
| Man-in-the-Middle (MITM) | Intercept login credentials (e.g., public Wi-Fi) | HTTPS (TLS), VPNs |
| Credential Stuffing | Use leaked passwords from other sites | Password managers, unique passwords |
| Spoofing | Fake login pages (e.g., fake eSewa site) | Check URL, use app instead of browser |
Real Example: 2021 Ncell SIM Hack
- Attack: SIM swapping (fraudsters tricked Ncell to transfer victim’s number to their SIM).
- Impact: Hackers accessed OTPs for banking apps.
- Fix: Ncell now requires biometric + OTP for SIM transfers.
8. Best Practices for Secure Authentication
- Enforce MFA: Especially for admin accounts (e.g., NTC network admins).
- Password Policies:
- Minimum 12 characters.
- No reuse across sites (use a password manager like Bitwarden).
- Regular Audits: Review access logs (e.g., who accessed NEPSE’s trading data).
- Educate Users: Train employees on phishing (e.g., Ncell’s annual security workshops).
- Zero Trust: Assume breach → verify every access request (e.g., Google BeyondCorp).
## In the real world
eSewa’s MFA for Payments
- Idea: Multi-factor authentication (password + OTP).
- How: User enters PIN → eSewa sends OTP via SMS → transaction only proceeds if OTP matches.
- Impact: Reduced fraud by 60% (per eSewa’s 2022 report).
Ncell’s Role-Based Access for Engineers
- Idea: Role-Based Access Control (RBAC).
- How: Network engineers get access to router configs but not customer billing data.
- Impact: Prevents insider threats (e.g., an engineer modifying call records).
Khalti’s Biometric Login for Merchants
- Idea: Biometric authentication (fingerprint).
- How: Small shop owners log in to Khalti Merchant Dashboard via fingerprint (no passwords).
- Challenge: Some older users struggle with fingerprint scanners → Khalti added PIN fallback.
Nepal Rastra Bank’s PCI DSS Compliance
- Idea: Secure authentication for online banking.
- How: Banks use 3D Secure (3DS) for card payments (extra OTP step).
- Result: Fraudulent transactions dropped by 40% since 2020.
## Exam Tip
How this unit is tested in TU/PU/NEB exams:
Definitions: Expect questions on MFA, RBAC, Kerberos, and biometrics. Memorize key terms and their differences.
- Example Question: "Differentiate between DAC and MAC with examples from Nepali organizations."
- Answer Focus: Use NTC (MAC) vs. Google Drive (DAC).
Scenario-Based Questions:
- Example: "A Daraz employee can access order details but not financial records. What access control model is this?"
- Answer: Role-Based Access Control (RBAC).
Attack Mitigation:
- Example: "How would you secure a bank’s online login system from credential stuffing?"
- Answer: MFA + password managers + rate limiting.
Legal Compliance:
- Example: "Which Nepali law requires MFA for transactions over Rs. 50,000?"
- Answer: Electronic Transactions Act 2008.
Diagrams:
- Draw Kerberos flow or RBAC hierarchy (e.g., for a university’s student portal).
- Tip: Label all components (e.g., "Auth Server," "Service Ticket").
Common Mistakes to Avoid:
- Confusing authentication (proving identity) with authorization (granting permissions).
- Forgetting real-world examples (examiners love eSewa, Ncell, or bank cases).
- Overcomplicating answers—stick to one clear example per point.
Final Checklist for Full Marks: ✅ Define MFA, RBAC, and Kerberos with examples. ✅ Compare DAC vs. MAC vs. RBAC in a table. ✅ Explain how biometrics work and their limitations. ✅ Describe one attack (e.g., phishing) and its defense. ✅ Link one concept to a Nepali law (e.g., PCI DSS for banks). ✅ Draw one diagram (Kerberos flow or RBAC hierarchy).
Based on the TU BIM syllabus for Information Security (IT244), unit 7.
Discussion
Loading…