NET Centric ComputingUnit 95 min read

ASP.NET Core Security: Authentication, Authorization, Identity & Threats

Unit 9 of NET Centric Computing covers securing ASP.NET Core applications through authentication (Identity, OAuth, JWT), authorization (policies, roles, claims), data protection, and mitigating common threats like XSS, CSRF, and injection attacks. Real-world examples from eSewa, Ncell, and global platforms illustrate i

Key Concepts and Mechanisms

Authentication: Verifying User Identity

Authentication ensures that users are who they claim to be. In ASP.NET Core, this is typically handled via Identity Framework (built-in) or third-party providers (Google, Facebook, etc.).

1. ASP.NET Core Identity

  • Built-in framework for managing user accounts, roles, and claims.
  • Uses Entity Framework Core to store user data in a database.
  • Supports password hashing, email confirmation, and two-factor authentication (2FA).
classDiagram
    class User {
        +string UserName
        +string Email
        +string PasswordHash
        +bool EmailConfirmed
    }
    class Role {
        +string Name
    }
    class Claim {
        +string Type
        +string Value
    }
    User "1" -- "0..*" Role : has
    User "1" -- "0..*" Claim : has

2. External Authentication (OAuth 2.0 / OpenID Connect)

  • Allows users to log in using third-party providers (Google, Facebook, Microsoft).
  • Uses JWT (JSON Web Tokens) for stateless authentication.
  • Example: eSewa uses OAuth to integrate with banks for secure transactions.
sequenceDiagram
    participant User
    participant ClientApp
    participant AuthServer
    participant ResourceServer

    User->>ClientApp: Requests login via Google
    ClientApp->>AuthServer: Redirects to Google OAuth
    AuthServer-->>ClientApp: Returns Access Token (JWT)
    ClientApp->>ResourceServer: Sends JWT for API access
    ResourceServer-->>ClientApp: Returns protected data

Worked Example: eSewa’s Secure Login

  • When a user logs into eSewa via their bank, the system uses OAuth 2.0 to authenticate.
  • The bank issues a JWT token, which eSewa validates before granting access.
  • If the token is invalid, the request is rejected.

Authorization: Controlling Access

Authorization determines what an authenticated user can do. ASP.NET Core provides multiple ways to enforce access control:

1. Role-Based Authorization

  • Users are assigned roles (e.g., Admin, User, Guest).
  • Policies check if a user has a specific role before granting access.
// Example: Require "Admin" role
[Authorize(Roles = "Admin")]
public IActionResult AdminDashboard() { ... }

2. Policy-Based Authorization

  • More flexible than roles; uses claims (e.g., CanEdit, IsPremiumUser).
  • Defined in Startup.cs or Program.cs.
services.AddAuthorization(options =>
{
    options.AddPolicy("RequirePremium", policy =>
        policy.RequireClaim("PremiumUser"));
});

3. Claims-Based Authorization

  • Users have claims (key-value pairs) attached to their identity.
  • Example: A user with Claim("Age", "18+") can access adult content.

Securing Data and APIs

1. Data Protection (Encryption)

  • Anti-Forgery Tokens: Prevent CSRF (Cross-Site Request Forgery) attacks.
  • HTTPS: Ensures data is encrypted in transit.
  • JWT Validation: Ensures tokens are not tampered with.

2. API Security (OData, Swagger)

  • Swagger/OpenAPI: Document APIs and enforce authentication.
  • CORS (Cross-Origin Resource Sharing): Restrict which domains can access your API.

Worked Example: Ncell’s API Security

  • Ncell’s developer portal uses OAuth 2.0 for API access.
  • Each request must include a valid JWT token in the Authorization header.
  • If missing or invalid, the API returns 401 Unauthorized.

Common Threats and Mitigations

Threat Description Mitigation in ASP.NET Core
XSS (Cross-Site Scripting) Inject malicious scripts into web pages. Use HtmlEncoder and AntiForgeryToken.
CSRF Trick users into executing unwanted actions. Use [ValidateAntiForgeryToken] and same-site cookies.
SQL Injection Malicious SQL queries via user input. Use Entity Framework Core (parameterized queries).
Man-in-the-Middle (MITM) Intercept communication between client and server. Enforce HTTPS and HSTS.

In the Real World

  1. eSewa (Nepal)

    • Uses OAuth 2.0 to integrate with banks for secure transactions.
    • JWT tokens are issued after successful authentication, ensuring stateless security.
  2. Ncell (Nepal)

    • Secures its API using OAuth 2.0 and JWT validation.
    • Prevents unauthorized access to user data via role-based policies.
  3. Google (Global)

    • Uses OpenID Connect for single sign-on (SSO) across services (Gmail, Drive).
    • Claims-based authorization ensures users access only permitted features.

Exam Tip

  • Authentication vs. Authorization:
    • Authentication = "Who are you?" (Identity, OAuth, JWT).
    • Authorization = "What can you do?" (Roles, Policies, Claims).
  • Common Exam Questions:
    • Explain how ASP.NET Core Identity stores user data.
    • Compare role-based vs. policy-based authorization.
    • Describe how JWT works in OAuth 2.0.
    • List three security threats and their mitigations in ASP.NET Core.
  • Practical Scenario:
    • Given a scenario (e.g., "Design a secure login system for a bank"), explain:
      1. How OAuth 2.0 would be used.
      2. How JWT tokens would be validated.
      3. How role-based policies would restrict access.

Key Takeaways:

  • ASP.NET Core Identity manages user accounts securely.
  • OAuth 2.0/OpenID Connect enables third-party logins (e.g., Google, Facebook).
  • JWT provides stateless authentication for APIs.
  • Role-based and policy-based authorization control access.
  • Always use HTTPS, anti-forgery tokens, and parameterized queries to prevent attacks.

Based on the TU BIT syllabus for NET Centric Computing (BIT351), unit 9.

Discussion

Loading…