Network SecurityUnit 211 min read

User Authentication: Methods, Protocols & Security

Unit 2 of Network Security explores authentication mechanisms—passwords, biometrics, tokens, and multi-factor systems—how they work, their vulnerabilities, and real-world deployments in banking, e-commerce, and government services like eSewa and Ncell.

TAKEAWAYS:

  • Authentication verifies user identity via something you know (passwords), have (tokens), or are (biometrics), with multi-factor (MFA) combining two or more.
  • Weak passwords, phishing, and replay attacks exploit single-factor systems; MFA mitigates these risks by requiring multiple proofs.
  • Kerberos and OAuth use ticket-based and token-based authentication, respectively, to securely delegate access without exposing credentials.
  • Biometric systems (fingerprint, iris) balance security and convenience but face challenges like spoofing and false rejection rates.
  • Password policies (length, complexity, expiration) and hashing (SHA-256, bcrypt) defend against brute-force attacks.
  • Real-world systems like eSewa’s OTP (time-based tokens) and Ncell’s SIM-based authentication demonstrate layered security in Nepalese services.

1. Authentication Fundamentals

Authentication is the process of verifying a user’s claimed identity before granting access to a system or resource. It relies on three core factors:

  1. Something you know (e.g., passwords, PINs).
  2. Something you have (e.g., smart cards, OTP tokens).
  3. Something you are (e.g., fingerprints, facial recognition).

Why Authentication Matters

  • Prevents unauthorized access (e.g., a hacker guessing a password).
  • Enables accountability (e.g., tracking who accessed a bank account).
  • Supports compliance (e.g., GDPR, PCI-DSS for financial transactions).

Authentication vs. Authorization vs. Accounting

Term Definition Example
Authentication Proves who you are. Logging in with a username and password.
Authorization Defines what you can do. A bank teller accessing customer accounts.
Accounting Tracks what you did. Audit logs of login attempts.

2. Authentication Methods

A. Password-Based Authentication

How it works:

  1. User enters a secret (password).
  2. System compares it against a stored hash (e.g., bcrypt, SHA-256).
  3. If matched, access is granted.

Weaknesses:

  • Brute-force attacks: Trying all possible combinations.
  • Phishing: Tricking users into revealing passwords.
  • Replay attacks: Capturing and reusing credentials.

Example:

  • eSewa login: Uses a password + OTP (multi-factor).
  • Ncell MyAccount: Requires a password + registered phone number for OTP.

B. Token-Based Authentication

Tokens are temporary credentials issued by an authentication server. Two common types:

  1. Hardware Tokens (e.g., RSA SecurID): Generate one-time passwords (OTP).
  2. Software Tokens (e.g., Google Authenticator): Time-based OTPs (TOTP).

How TOTP Works (e.g., eSewa OTP):

sequenceDiagram
    User->>Server: Requests login
    Server->>User: Sends OTP via SMS
    User->>Server: Enters OTP
    Server-->>User: Grants access if OTP matches

Advantages:

  • Single-use tokens prevent replay attacks.
  • No need to remember complex passwords.

Disadvantages:

  • SIM-swapping attacks can bypass SMS-based OTPs.
  • Hardware tokens are costly.

C. Biometric Authentication

Uses unique physical traits to verify identity:

  • Fingerprint (e.g., smartphone unlock).
  • Facial recognition (e.g., iPhone Face ID).
  • Iris/retina scan (high-security applications).

How it works:

  1. Sensor captures biometric data.
  2. System compares it to a template (stored hash of the trait).
  3. If match > threshold, access granted.

Challenges:

  • False Acceptance Rate (FAR): System accepts an impostor.
  • False Rejection Rate (FRR): Legitimate user denied access.
  • Spoofing: Fake fingerprints (e.g., silicone molds).

Example:

  • Ncell’s facial recognition for SIM registration.
  • Nepal Police’s fingerprint database for criminal records.

D. Multi-Factor Authentication (MFA)

Combines two or more authentication factors for stronger security.

Something You KnowSomething You HaveSomething You Are
MFA combines three authentication factors

Example Scenarios:

Service Factor 1 Factor 2 Factor 3
eSewa Password OTP (SMS) Fingerprint (optional)
Ncell MyAccount Password Registered phone number PIN
Google Accounts Password TOTP (Authenticator) Security key (YubiKey)

Why MFA?

  • Reduces breach risk: Even if one factor is compromised, others remain secure.
  • Compliance: Required for PCI-DSS (payment systems) and GDPR.

3. Authentication Protocols

A. Kerberos (Ticket-Based Authentication)

Used in Windows Active Directory and Linux environments.

How it works:

  1. User requests a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC).
  2. KDC issues TGT encrypted with the Ticket Granting Service (TGS) key.
  3. User requests a service ticket for the target server.
  4. Server validates the ticket and grants access.
sequenceDiagram
    User->>KDC: Request TGT (username/password)
    KDC-->>User: TGT (encrypted)
    User->>TGS: Request service ticket (TGT)
    TGS-->>User: Service ticket (encrypted)
    User->>Server: Present ticket
    Server-->>User: Grant access

Advantages:

  • No password transmission over the network.
  • Supports single sign-on (SSO).

Disadvantages:

  • Complex setup (requires KDC).
  • Time synchronization issues.

B. OAuth (Token-Based Delegated Authentication)

Used by Google, Facebook, and eSewa for third-party logins.

How it works:

  1. User clicks "Login with Google" on a website (e.g., Daraz).
  2. Daraz redirects to Google’s OAuth server.
  3. Google asks for permission to share data.
  4. Google issues an access token to Daraz.
  5. Daraz uses the token to fetch user data from Google’s API.
sequenceDiagram
    User->>Daraz: Click "Login with Google"
    Daraz->>Google: Redirect to OAuth
    Google->>User: Request permission
    User->>Google: Approve
    Google-->>Daraz: Access token
    Daraz->>Google: Fetch user data (using token)
    Google-->>Daraz: User profile

Advantages:

  • Users don’t share passwords with third parties.
  • Granular permissions (e.g., "Allow Daraz to see your email only").

Disadvantages:

  • Token theft: If a token is leaked, attackers can impersonate the user.
  • Revocability: Tokens must be invalidated if compromised.

4. Password Security Best Practices

A. Password Policies

Policy Example Purpose
Minimum length 12+ characters Resists brute force.
Complexity Mix of uppercase, lowercase, symbols Harder to guess.
Expiration Change every 90 days Reduces long-term exposure.
Reuse prohibition Block common passwords (e.g., "123456") Prevents credential stuffing.

B. Password Hashing

Never store passwords in plaintext! Instead, use one-way hashing:

  • SHA-256: Fast but vulnerable to rainbow tables.
  • bcrypt: Slow (intentional delay) and salted.

Example:

# bcrypt example (Python)
import bcrypt
password = b"my_secure_password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
# Stored in DB: $2b$12$N9qo8uLOickgx2ZMRZoMy...

Why salting?

  • Prevents rainbow table attacks (precomputed hashes).
  • Example: Same password has different hashes due to unique salts.

5. Common Authentication Attacks

Attack How it works Mitigation
Brute Force Trying all possible passwords. Enforce complexity, rate-limiting.
Phishing Tricking users into revealing passwords. User education, MFA.
Replay Attack Capturing and reusing valid credentials. One-time tokens (OTP), timestamps.
Man-in-the-Middle (MITM) Intercepting credentials in transit. HTTPS, VPNs, certificate pinning.
Credential Stuffing Using leaked passwords from other breaches. Password managers, breach monitoring.

6. Real-World Applications in Nepal

A. eSewa: Multi-Factor Authentication

  • Factor 1: Password (set by user).
  • Factor 2: OTP sent via SMS (time-based, expires in 5 mins).
  • Factor 3 (optional): Fingerprint on mobile app.
  • Why it works: Even if a password is leaked, the OTP adds a layer of security.

B. Ncell MyAccount: SIM-Based Authentication

  • Factor 1: Password.
  • Factor 2: Registered phone number (OTP sent to the same SIM).
  • Risk: SIM-swapping attacks can bypass this if the attacker controls the SIM.

C. NEPSE Trading: Biometric + OTP

  • Investors use fingerprint + OTP to log into trading accounts.
  • Prevents unauthorized trades even if passwords are compromised.

7. Worked Example: Securing a Bank Login

Scenario: A customer logs into Nabil Bank’s online portal.

  1. Step 1: User enters username and password.
    • Bank checks password against bcrypt hash.
  2. Step 2: Bank sends an OTP to the registered phone.
    • OTP expires in 5 minutes.
  3. Step 3: User enters OTP.
    • Bank verifies OTP and grants access.
  4. Step 4: Bank logs the session and sets a timeout.

Security Layers:

  • Password: Something you know.
  • OTP: Something you have (phone).
  • Session timeout: Limits exposure if device is stolen.

8. Exam Tip

What to Expect in TU/PU Exams

  1. Definitions: Be ready to explain Kerberos, OAuth, MFA, and biometrics.
  2. Diagrams: Draw sequence diagrams for Kerberos/OAuth and state diagrams for authentication flows.
  3. Comparisons: Compare passwords vs. tokens vs. biometrics in a table.
  4. Scenario-Based Questions:
    • "How would you secure eSewa’s login?" → MFA (password + OTP + biometrics).
    • "Explain how a replay attack works and how TOTP prevents it."
  5. Attack Mitigations: Know how to defend against brute force, phishing, and MITM.

Common Pitfalls:

  • Forgetting to mention salting in password hashing.
  • Confusing authentication (proving identity) with authorization (granting access).
  • Not explaining why MFA is better than single-factor.

Quick Revision Checklist

  • Can you draw a Kerberos sequence diagram?
  • Do you know the three factors of authentication?
  • Can you list two real-world Nepalese examples of MFA?
  • What’s the difference between SHA-256 and bcrypt?
  • How does OAuth work without exposing passwords?

Based on the TU BIT syllabus for Network Security, unit 2.

Discussion

Loading…