BIT303 Information Security

Information SecurityUnit 711 min read

Access Control & Authentication: Mechanisms, Models & Threats

Unit 7 of Information Security: Explores how systems enforce access control (subjects, objects, rights) and authenticate users (passwords, biometrics, tokens), comparing RBAC vs. ABAC, multi-factor authentication, and real-world attacks like dictionary attacks—with worked examples from eSewa, banks, and Daraz.

TAKEAWAYS:

  • Authentication verifies identity (e.g., passwords, biometrics), while access control enforces permissions (e.g., read/write) on objects like files or systems.
  • Role-Based Access Control (RBAC) assigns permissions based on job roles (e.g., admin vs. user), while Attribute-Based Access Control (ABAC) uses dynamic attributes (e.g., time, location).
  • Multi-Factor Authentication (MFA) combines two or more factors (knowledge, possession, inherence) to thwart brute-force attacks (e.g., eSewa’s SMS + OTP).
  • Dictionary attacks exploit weak passwords by checking against precomputed lists (offline) or repeated online guesses, while phishing tricks users into revealing credentials.
  • Biometric authentication (fingerprint, iris) is tamper-resistant but vulnerable to spoofing (e.g., Pathao’s driver verification).
  • Trust frameworks (e.g., NEPSE’s KYC) standardize identity verification across systems to reduce fraud.

1. Definitions: Authentication vs. Access Control

Authentication is the process of verifying a user’s claimed identity (e.g., logging into eSewa with a username/password). Access control is the enforcement of permissions to protect objects (e.g., restricting a Daraz warehouse worker from editing inventory).

What: Prove identity (e.g., 'Are you User X?')PasswordsBiometricsTokensMethodsExample: Ncell’s SIM registration (PIN + biometric)AuthenticationWhat: Grant/revoke access to resourcesRBACABACMACModelsBank teller (RBAC: can process loans)Intern (ABAC: can only file reports)ExampleAccess ControlAuthentication & Access Control
Hierarchical comparison of Authentication vs. Access Control with real-world Nepali examples

Key Terms:

  • Subject: Active entity (user, process) requesting access (e.g., a Daraz customer).
  • Object: Passive resource (file, database) being accessed (e.g., a customer’s order history).
  • Access Rights: Permissions like read, write, execute (e.g., a Pathao driver can only view trip logs, not admin tools).

2. Authentication Mechanisms

Authentication relies on three factors:

  1. Something you know (password, PIN): Vulnerable to phishing (e.g., fake eSewa login pages).
  2. Something you have (smart card, OTP): Used by NTC for employee badges.
  3. Something you are (fingerprint, retina): Biometrics are hard to replicate but can be spoofed (e.g., silicone fingerprints).
stateDiagram-v2
    [*] --> Authenticated
    Authenticated --> Unauthenticated: Factor fails (e.g., wrong PIN)
    Unauthenticated --> Authenticated: Correct factor (e.g., fingerprint scan)
    Authenticated --> [*]: Session expires or logout

Biometric Authentication:

  • Fingerprint: Used in Android phones and Ncell’s SIM unlock.
  • Iris/Retina: Highly secure but expensive (e.g., airport biometric checkpoints).
  • Voice/Gait: Less common but used in military systems.

Advantages:

  • Harder to steal than passwords.
  • No need to remember tokens.

Disadvantages:

  • Spoofing: Fake fingerprints (e.g., gelatin molds).
  • False rejects: System rejects legitimate users (e.g., Pathao driver’s fingerprint smudged).

3. Access Control Models

Model Description Example
Discretionary (DAC) Owner grants permissions (e.g., sharing a Google Doc). A Daraz employee shares a sales report with colleagues.
Mandatory (MAC) System enforces strict rules (e.g., military clearance). NEPSE restricts stock data access by user rank.
Role-Based (RBAC) Permissions tied to job roles (e.g., admin, editor). Bank tellers (RBAC: can process loans) vs. clerks (RBAC: can only file).
Attribute-Based (ABAC) Permissions based on dynamic attributes (time, location, device). NTC allows employees to access VPN only during office hours.
Example: Daraz warehouse picker (role: 'inventory updater')Rule: Permissions tied to roles (e.g., 'manager' vs. 'cashieRBAC (Role-Based)Example: Pathao driver (attributes: 'license type', 'vehicleRule: Dynamic permissions based on attributesABAC (Attribute-Based)Example: Government data access (security clearance levels)Rule: System-enforced, non-negotiable hierarchyMAC (Mandatory)Access Control Models
Comparison of access control models with Nepali service examples

Worked Example: Daraz Warehouse Access

  • RBAC: A picker has read/write access to inventory but no delete rights.
  • ABAC: A picker can only access shelves in Zone A during 8 AM–5 PM (time + location attributes).

4. Multi-Factor Authentication (MFA)

MFA combines two or more factors to reduce risk. Example: eSewa’s SMS OTP + fingerprint for high-value transactions.

sequenceDiagram
    participant User
    participant eSewa
    participant SMS_Gateway
    participant Biometric_Sensor

    User->>eSewa: Enters username/password
    eSewa-->>User: Requests OTP
    eSewa->>SMS_Gateway: Send OTP to phone
    User->>Biometric_Sensor: Scans fingerprint
    Biometric_Sensor-->>eSewa: Verifies biometric
    eSewa-->>User: Grant access (if OTP + biometric match)

Why MFA?

  • Single-factor failure: Even if a password is stolen, the second factor (e.g., OTP) blocks access.
  • Real-world use: Ncell’s SIM registration requires PIN + biometric for security.

5. Password-Based Authentication: Attacks

Attack Type Description Example
Online Dictionary Repeatedly guesses passwords (e.g., "123456"). Slows down with delays. Hacker tries "password" → "admin" → "qwerty" on a bank login.
Offline Dictionary Steals hashed passwords and checks against a precomputed list. Ncell database breach: attackers crack hashes offline with GPU clusters.
Brute Force Exhausts all possible combinations (e.g., 8-character alphanumeric). Unfeasible for strong passwords but works on weak ones (e.g., "1111").
Phishing Tricks users into revealing passwords (e.g., fake eSewa login page). User enters credentials on a spoofed esewa.com.attacker.com site.

Mitigations:

  • Salting: Adds random data to passwords before hashing (e.g., bcrypt).
  • Rate Limiting: Blocks repeated login attempts (e.g., WhatsApp’s 5-minute lockout).
  • User Education: Warn users about phishing (e.g., NTC’s cybersecurity campaigns).

6. Trust Frameworks and Identity Management

A trust framework standardizes how identities are verified across systems. Example: NEPSE’s KYC (Know Your Customer) requires:

  1. Government-issued ID (passport, citizenship).
  2. Biometric verification (fingerprint/iris).
  3. Third-party validation (e.g., bank account linkage).
verifiesplacesfollowsUSERIDENTITY_PROVIDERTRUST_FRAMEWORKTRANSACTION
NEPSE KYC trust framework relationships (simplified)

Real-World Example: NEPSE’s Trust Framework

  • Why? Prevents fake accounts from trading stocks.
  • How? Uses attribute-based access (only verified users can trade).

7. Issues in User Authentication

Issue Description Impact
Password Reuse Using the same password across sites (e.g., eSewa + Facebook). Single breach compromises multiple accounts.
Credential Stuffing Attackers use leaked passwords from one site on others (e.g., LinkedIn → eSewa). Mass account takeovers.
Session Hijacking Stealing a session token (e.g., via malware). Unauthorized access to active sessions (e.g., Pathao driver dashboard).
Social Engineering Manipulating users into sharing secrets (e.g., "Your account is locked!"). Bypasses technical controls.
011.2522.533.7545Password Weakness45Biometric Spoofing20Token Theft15Social Engineering20
Common authentication failure causes in Nepal (approximate %)

8. Digital Signatures in Message Authentication

A digital signature proves:

  1. The message came from the claimed sender.
  2. The message was not altered in transit.

How it works:

  1. Sender hashes the message and encrypts it with their private key.
  2. Recipient decrypts with the sender’s public key and verifies the hash.
sequenceDiagram
    participant Sender
    participant Recipient
    participant CA

    Sender->>CA: Requests digital certificate (public key)
    CA-->>Sender: Issues certificate
    Sender->>Recipient: Sends (Message || Signature)
    Recipient->>CA: Verifies Sender’s public key
    Recipient->>Recipient: Decrypts signature with public key
    Recipient->>Recipient: Rehashes message and compares

Example: NEPSE Stock Trade

  • A broker signs a trade order with their private key.
  • NEPSE verifies the signature using the broker’s public key to ensure authenticity.

In the real world

  1. eSewa’s MFA for High-Value Transactions

    • Idea: Uses two-factor authentication (SMS OTP + fingerprint) for payments over ₹10,000.
    • Why? Prevents fraud when a password is stolen (e.g., if a user’s phone is hacked).
  2. Ncell’s SIM Registration with Biometrics

    • Idea: Requires biometric verification (fingerprint) alongside PIN for new SIMs.
    • Why? Reduces SIM swapping attacks (where fraudsters hijack phone numbers).
  3. Daraz’s Warehouse Access Control

    • Idea: Uses role-based access control (RBAC) to limit employees’ actions (e.g., pickers can scan but not edit orders).
    • Worked Example:
      • Scenario: A picker scans a barcode to retrieve an item.
      • RBAC Rule: Only "Picker" role has read access to inventory; "Manager" has read/write/delete.
      • Impact: Prevents accidental or malicious data changes.

Exam Tip

  • Focus on comparisons: Always explain RBAC vs. ABAC with a real example (e.g., bank vs. NTC).
  • Link attacks to real products: For dictionary attacks, mention Ncell’s password policies or eSewa’s rate limiting.
  • Diagrams are worth marks: Draw a sequence diagram for MFA or an ER diagram for a trust framework.
  • Define terms clearly: For "subject/object," use Daraz warehouse (subject = picker, object = inventory).
  • Worked examples: Practice tracing a Pathao driver’s login (password + biometric) or a NEPSE trade order (digital signature).

Based on the TU BIT syllabus for Information Security (BIT303), unit 7.

Discussion

Loading…