Information SecurityUnit 711 min read
Access Control & Authentication: Mechanisms, Models & Threats
Unit 7 of Information Security: Explores how systems enforce access control (subjects, objects, rights) and authenticate users (passwords, biometrics, tokens), comparing RBAC vs. ABAC, multi-factor authentication, and real-world attacks like dictionary attacks—with worked examples from eSewa, banks, and Daraz.
TAKEAWAYS:
- Authentication verifies identity (e.g., passwords, biometrics), while access control enforces permissions (e.g., read/write) on objects like files or systems.
- Role-Based Access Control (RBAC) assigns permissions based on job roles (e.g., admin vs. user), while Attribute-Based Access Control (ABAC) uses dynamic attributes (e.g., time, location).
- Multi-Factor Authentication (MFA) combines two or more factors (knowledge, possession, inherence) to thwart brute-force attacks (e.g., eSewa’s SMS + OTP).
- Dictionary attacks exploit weak passwords by checking against precomputed lists (offline) or repeated online guesses, while phishing tricks users into revealing credentials.
- Biometric authentication (fingerprint, iris) is tamper-resistant but vulnerable to spoofing (e.g., Pathao’s driver verification).
- Trust frameworks (e.g., NEPSE’s KYC) standardize identity verification across systems to reduce fraud.
1. Definitions: Authentication vs. Access Control
Authentication is the process of verifying a user’s claimed identity (e.g., logging into eSewa with a username/password). Access control is the enforcement of permissions to protect objects (e.g., restricting a Daraz warehouse worker from editing inventory).
Key Terms:
- Subject: Active entity (user, process) requesting access (e.g., a Daraz customer).
- Object: Passive resource (file, database) being accessed (e.g., a customer’s order history).
- Access Rights: Permissions like read, write, execute (e.g., a Pathao driver can only view trip logs, not admin tools).
2. Authentication Mechanisms
Authentication relies on three factors:
- Something you know (password, PIN): Vulnerable to phishing (e.g., fake eSewa login pages).
- Something you have (smart card, OTP): Used by NTC for employee badges.
- Something you are (fingerprint, retina): Biometrics are hard to replicate but can be spoofed (e.g., silicone fingerprints).
stateDiagram-v2
[*] --> Authenticated
Authenticated --> Unauthenticated: Factor fails (e.g., wrong PIN)
Unauthenticated --> Authenticated: Correct factor (e.g., fingerprint scan)
Authenticated --> [*]: Session expires or logoutBiometric Authentication:
- Fingerprint: Used in Android phones and Ncell’s SIM unlock.
- Iris/Retina: Highly secure but expensive (e.g., airport biometric checkpoints).
- Voice/Gait: Less common but used in military systems.
Advantages:
- Harder to steal than passwords.
- No need to remember tokens.
Disadvantages:
- Spoofing: Fake fingerprints (e.g., gelatin molds).
- False rejects: System rejects legitimate users (e.g., Pathao driver’s fingerprint smudged).
3. Access Control Models
| Model | Description | Example |
|---|---|---|
| Discretionary (DAC) | Owner grants permissions (e.g., sharing a Google Doc). | A Daraz employee shares a sales report with colleagues. |
| Mandatory (MAC) | System enforces strict rules (e.g., military clearance). | NEPSE restricts stock data access by user rank. |
| Role-Based (RBAC) | Permissions tied to job roles (e.g., admin, editor). | Bank tellers (RBAC: can process loans) vs. clerks (RBAC: can only file). |
| Attribute-Based (ABAC) | Permissions based on dynamic attributes (time, location, device). | NTC allows employees to access VPN only during office hours. |
Worked Example: Daraz Warehouse Access
- RBAC: A picker has read/write access to inventory but no delete rights.
- ABAC: A picker can only access shelves in Zone A during 8 AM–5 PM (time + location attributes).
4. Multi-Factor Authentication (MFA)
MFA combines two or more factors to reduce risk. Example: eSewa’s SMS OTP + fingerprint for high-value transactions.
sequenceDiagram
participant User
participant eSewa
participant SMS_Gateway
participant Biometric_Sensor
User->>eSewa: Enters username/password
eSewa-->>User: Requests OTP
eSewa->>SMS_Gateway: Send OTP to phone
User->>Biometric_Sensor: Scans fingerprint
Biometric_Sensor-->>eSewa: Verifies biometric
eSewa-->>User: Grant access (if OTP + biometric match)Why MFA?
- Single-factor failure: Even if a password is stolen, the second factor (e.g., OTP) blocks access.
- Real-world use: Ncell’s SIM registration requires PIN + biometric for security.
5. Password-Based Authentication: Attacks
| Attack Type | Description | Example |
|---|---|---|
| Online Dictionary | Repeatedly guesses passwords (e.g., "123456"). Slows down with delays. | Hacker tries "password" → "admin" → "qwerty" on a bank login. |
| Offline Dictionary | Steals hashed passwords and checks against a precomputed list. | Ncell database breach: attackers crack hashes offline with GPU clusters. |
| Brute Force | Exhausts all possible combinations (e.g., 8-character alphanumeric). | Unfeasible for strong passwords but works on weak ones (e.g., "1111"). |
| Phishing | Tricks users into revealing passwords (e.g., fake eSewa login page). | User enters credentials on a spoofed esewa.com.attacker.com site. |
Mitigations:
- Salting: Adds random data to passwords before hashing (e.g., bcrypt).
- Rate Limiting: Blocks repeated login attempts (e.g., WhatsApp’s 5-minute lockout).
- User Education: Warn users about phishing (e.g., NTC’s cybersecurity campaigns).
6. Trust Frameworks and Identity Management
A trust framework standardizes how identities are verified across systems. Example: NEPSE’s KYC (Know Your Customer) requires:
- Government-issued ID (passport, citizenship).
- Biometric verification (fingerprint/iris).
- Third-party validation (e.g., bank account linkage).
Real-World Example: NEPSE’s Trust Framework
- Why? Prevents fake accounts from trading stocks.
- How? Uses attribute-based access (only verified users can trade).
7. Issues in User Authentication
| Issue | Description | Impact |
|---|---|---|
| Password Reuse | Using the same password across sites (e.g., eSewa + Facebook). | Single breach compromises multiple accounts. |
| Credential Stuffing | Attackers use leaked passwords from one site on others (e.g., LinkedIn → eSewa). | Mass account takeovers. |
| Session Hijacking | Stealing a session token (e.g., via malware). | Unauthorized access to active sessions (e.g., Pathao driver dashboard). |
| Social Engineering | Manipulating users into sharing secrets (e.g., "Your account is locked!"). | Bypasses technical controls. |
8. Digital Signatures in Message Authentication
A digital signature proves:
- The message came from the claimed sender.
- The message was not altered in transit.
How it works:
- Sender hashes the message and encrypts it with their private key.
- Recipient decrypts with the sender’s public key and verifies the hash.
sequenceDiagram
participant Sender
participant Recipient
participant CA
Sender->>CA: Requests digital certificate (public key)
CA-->>Sender: Issues certificate
Sender->>Recipient: Sends (Message || Signature)
Recipient->>CA: Verifies Sender’s public key
Recipient->>Recipient: Decrypts signature with public key
Recipient->>Recipient: Rehashes message and comparesExample: NEPSE Stock Trade
- A broker signs a trade order with their private key.
- NEPSE verifies the signature using the broker’s public key to ensure authenticity.
In the real world
eSewa’s MFA for High-Value Transactions
- Idea: Uses two-factor authentication (SMS OTP + fingerprint) for payments over ₹10,000.
- Why? Prevents fraud when a password is stolen (e.g., if a user’s phone is hacked).
Ncell’s SIM Registration with Biometrics
- Idea: Requires biometric verification (fingerprint) alongside PIN for new SIMs.
- Why? Reduces SIM swapping attacks (where fraudsters hijack phone numbers).
Daraz’s Warehouse Access Control
- Idea: Uses role-based access control (RBAC) to limit employees’ actions (e.g., pickers can scan but not edit orders).
- Worked Example:
- Scenario: A picker scans a barcode to retrieve an item.
- RBAC Rule: Only "Picker" role has read access to inventory; "Manager" has read/write/delete.
- Impact: Prevents accidental or malicious data changes.
Exam Tip
- Focus on comparisons: Always explain RBAC vs. ABAC with a real example (e.g., bank vs. NTC).
- Link attacks to real products: For dictionary attacks, mention Ncell’s password policies or eSewa’s rate limiting.
- Diagrams are worth marks: Draw a sequence diagram for MFA or an ER diagram for a trust framework.
- Define terms clearly: For "subject/object," use Daraz warehouse (subject = picker, object = inventory).
- Worked examples: Practice tracing a Pathao driver’s login (password + biometric) or a NEPSE trade order (digital signature).
Based on the TU BIT syllabus for Information Security (BIT303), unit 7.
Discussion
Loading…