Network SecurityUnit 211 min read
User Authentication: Methods, Protocols & Security
Unit 2 of Network Security explores authentication mechanisms—passwords, biometrics, tokens, and multi-factor systems—how they work, their vulnerabilities, and real-world deployments in banking, e-commerce, and government services like eSewa and Ncell.
TAKEAWAYS:
- Authentication verifies user identity via something you know (passwords), have (tokens), or are (biometrics), with multi-factor (MFA) combining two or more.
- Weak passwords, phishing, and replay attacks exploit single-factor systems; MFA mitigates these risks by requiring multiple proofs.
- Kerberos and OAuth use ticket-based and token-based authentication, respectively, to securely delegate access without exposing credentials.
- Biometric systems (fingerprint, iris) balance security and convenience but face challenges like spoofing and false rejection rates.
- Password policies (length, complexity, expiration) and hashing (SHA-256, bcrypt) defend against brute-force attacks.
- Real-world systems like eSewa’s OTP (time-based tokens) and Ncell’s SIM-based authentication demonstrate layered security in Nepalese services.
1. Authentication Fundamentals
Authentication is the process of verifying a user’s claimed identity before granting access to a system or resource. It relies on three core factors:
- Something you know (e.g., passwords, PINs).
- Something you have (e.g., smart cards, OTP tokens).
- Something you are (e.g., fingerprints, facial recognition).
Why Authentication Matters
- Prevents unauthorized access (e.g., a hacker guessing a password).
- Enables accountability (e.g., tracking who accessed a bank account).
- Supports compliance (e.g., GDPR, PCI-DSS for financial transactions).
Authentication vs. Authorization vs. Accounting
| Term | Definition | Example |
|---|---|---|
| Authentication | Proves who you are. | Logging in with a username and password. |
| Authorization | Defines what you can do. | A bank teller accessing customer accounts. |
| Accounting | Tracks what you did. | Audit logs of login attempts. |
2. Authentication Methods
A. Password-Based Authentication
How it works:
- User enters a secret (password).
- System compares it against a stored hash (e.g., bcrypt, SHA-256).
- If matched, access is granted.
Weaknesses:
- Brute-force attacks: Trying all possible combinations.
- Phishing: Tricking users into revealing passwords.
- Replay attacks: Capturing and reusing credentials.
Example:
- eSewa login: Uses a password + OTP (multi-factor).
- Ncell MyAccount: Requires a password + registered phone number for OTP.
B. Token-Based Authentication
Tokens are temporary credentials issued by an authentication server. Two common types:
- Hardware Tokens (e.g., RSA SecurID): Generate one-time passwords (OTP).
- Software Tokens (e.g., Google Authenticator): Time-based OTPs (TOTP).
How TOTP Works (e.g., eSewa OTP):
sequenceDiagram
User->>Server: Requests login
Server->>User: Sends OTP via SMS
User->>Server: Enters OTP
Server-->>User: Grants access if OTP matchesAdvantages:
- Single-use tokens prevent replay attacks.
- No need to remember complex passwords.
Disadvantages:
- SIM-swapping attacks can bypass SMS-based OTPs.
- Hardware tokens are costly.
C. Biometric Authentication
Uses unique physical traits to verify identity:
- Fingerprint (e.g., smartphone unlock).
- Facial recognition (e.g., iPhone Face ID).
- Iris/retina scan (high-security applications).
How it works:
- Sensor captures biometric data.
- System compares it to a template (stored hash of the trait).
- If match > threshold, access granted.
Challenges:
- False Acceptance Rate (FAR): System accepts an impostor.
- False Rejection Rate (FRR): Legitimate user denied access.
- Spoofing: Fake fingerprints (e.g., silicone molds).
Example:
- Ncell’s facial recognition for SIM registration.
- Nepal Police’s fingerprint database for criminal records.
D. Multi-Factor Authentication (MFA)
Combines two or more authentication factors for stronger security.
Example Scenarios:
| Service | Factor 1 | Factor 2 | Factor 3 |
|---|---|---|---|
| eSewa | Password | OTP (SMS) | Fingerprint (optional) |
| Ncell MyAccount | Password | Registered phone number | PIN |
| Google Accounts | Password | TOTP (Authenticator) | Security key (YubiKey) |
Why MFA?
- Reduces breach risk: Even if one factor is compromised, others remain secure.
- Compliance: Required for PCI-DSS (payment systems) and GDPR.
3. Authentication Protocols
A. Kerberos (Ticket-Based Authentication)
Used in Windows Active Directory and Linux environments.
How it works:
- User requests a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC).
- KDC issues TGT encrypted with the Ticket Granting Service (TGS) key.
- User requests a service ticket for the target server.
- Server validates the ticket and grants access.
sequenceDiagram
User->>KDC: Request TGT (username/password)
KDC-->>User: TGT (encrypted)
User->>TGS: Request service ticket (TGT)
TGS-->>User: Service ticket (encrypted)
User->>Server: Present ticket
Server-->>User: Grant accessAdvantages:
- No password transmission over the network.
- Supports single sign-on (SSO).
Disadvantages:
- Complex setup (requires KDC).
- Time synchronization issues.
B. OAuth (Token-Based Delegated Authentication)
Used by Google, Facebook, and eSewa for third-party logins.
How it works:
- User clicks "Login with Google" on a website (e.g., Daraz).
- Daraz redirects to Google’s OAuth server.
- Google asks for permission to share data.
- Google issues an access token to Daraz.
- Daraz uses the token to fetch user data from Google’s API.
sequenceDiagram
User->>Daraz: Click "Login with Google"
Daraz->>Google: Redirect to OAuth
Google->>User: Request permission
User->>Google: Approve
Google-->>Daraz: Access token
Daraz->>Google: Fetch user data (using token)
Google-->>Daraz: User profileAdvantages:
- Users don’t share passwords with third parties.
- Granular permissions (e.g., "Allow Daraz to see your email only").
Disadvantages:
- Token theft: If a token is leaked, attackers can impersonate the user.
- Revocability: Tokens must be invalidated if compromised.
4. Password Security Best Practices
A. Password Policies
| Policy | Example | Purpose |
|---|---|---|
| Minimum length | 12+ characters | Resists brute force. |
| Complexity | Mix of uppercase, lowercase, symbols | Harder to guess. |
| Expiration | Change every 90 days | Reduces long-term exposure. |
| Reuse prohibition | Block common passwords (e.g., "123456") | Prevents credential stuffing. |
B. Password Hashing
Never store passwords in plaintext! Instead, use one-way hashing:
- SHA-256: Fast but vulnerable to rainbow tables.
- bcrypt: Slow (intentional delay) and salted.
Example:
# bcrypt example (Python)
import bcrypt
password = b"my_secure_password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
# Stored in DB: $2b$12$N9qo8uLOickgx2ZMRZoMy...
Why salting?
- Prevents rainbow table attacks (precomputed hashes).
- Example: Same password has different hashes due to unique salts.
5. Common Authentication Attacks
| Attack | How it works | Mitigation |
|---|---|---|
| Brute Force | Trying all possible passwords. | Enforce complexity, rate-limiting. |
| Phishing | Tricking users into revealing passwords. | User education, MFA. |
| Replay Attack | Capturing and reusing valid credentials. | One-time tokens (OTP), timestamps. |
| Man-in-the-Middle (MITM) | Intercepting credentials in transit. | HTTPS, VPNs, certificate pinning. |
| Credential Stuffing | Using leaked passwords from other breaches. | Password managers, breach monitoring. |
6. Real-World Applications in Nepal
A. eSewa: Multi-Factor Authentication
- Factor 1: Password (set by user).
- Factor 2: OTP sent via SMS (time-based, expires in 5 mins).
- Factor 3 (optional): Fingerprint on mobile app.
- Why it works: Even if a password is leaked, the OTP adds a layer of security.
B. Ncell MyAccount: SIM-Based Authentication
- Factor 1: Password.
- Factor 2: Registered phone number (OTP sent to the same SIM).
- Risk: SIM-swapping attacks can bypass this if the attacker controls the SIM.
C. NEPSE Trading: Biometric + OTP
- Investors use fingerprint + OTP to log into trading accounts.
- Prevents unauthorized trades even if passwords are compromised.
7. Worked Example: Securing a Bank Login
Scenario: A customer logs into Nabil Bank’s online portal.
- Step 1: User enters username and password.
- Bank checks password against bcrypt hash.
- Step 2: Bank sends an OTP to the registered phone.
- OTP expires in 5 minutes.
- Step 3: User enters OTP.
- Bank verifies OTP and grants access.
- Step 4: Bank logs the session and sets a timeout.
Security Layers:
- Password: Something you know.
- OTP: Something you have (phone).
- Session timeout: Limits exposure if device is stolen.
8. Exam Tip
What to Expect in TU/PU Exams
- Definitions: Be ready to explain Kerberos, OAuth, MFA, and biometrics.
- Diagrams: Draw sequence diagrams for Kerberos/OAuth and state diagrams for authentication flows.
- Comparisons: Compare passwords vs. tokens vs. biometrics in a table.
- Scenario-Based Questions:
- "How would you secure eSewa’s login?" → MFA (password + OTP + biometrics).
- "Explain how a replay attack works and how TOTP prevents it."
- Attack Mitigations: Know how to defend against brute force, phishing, and MITM.
Common Pitfalls:
- Forgetting to mention salting in password hashing.
- Confusing authentication (proving identity) with authorization (granting access).
- Not explaining why MFA is better than single-factor.
Quick Revision Checklist
- Can you draw a Kerberos sequence diagram?
- Do you know the three factors of authentication?
- Can you list two real-world Nepalese examples of MFA?
- What’s the difference between SHA-256 and bcrypt?
- How does OAuth work without exposing passwords?
Based on the TU BIT syllabus for Network Security, unit 2.
Discussion
Loading…