Information SecurityUnit 712 min read
Authentication & Access Control: Methods, Protocols & Security Models
Unit 7 of Information Security explores how systems verify identities (authentication) and restrict access (authorization), covering biometrics, tokens, multi-factor schemes, role-based models, and real-world attacks like credential stuffing—essential for securing digital assets in Nepal’s banking, e-commerce, and gove
Core Concepts: Authentication vs. Authorization
Authentication is the process of verifying who you are (e.g., proving you own a password or a fingerprint). Access control (authorization) is deciding what you’re allowed to do (e.g., granting a bank teller access to customer accounts but not loan approvals).
stateDiagram-v2
[*] --> Authenticate: "Who are you?"
Authenticate --> Verify: "Check credentials"
Verify --> Authorize: "Grant permissions"
Authorize --> Access: "Allow/deny actions"
Access --> [*]Authentication Factors: The 3 Pillars
Authentication relies on three factors, often combined for stronger security:
| Factor | Examples | Weaknesses |
|---|---|---|
| Something you know | Passwords, PINs, security questions | Easily stolen (phishing, shoulder-surfing) |
| Something you have | Smart cards, OTPs, hardware tokens | Lost/stolen (e.g., SIM swap fraud) |
| Something you are | Fingerprints, iris scans, voiceprints | Spoofing (e.g., fake fingerprints) |
Worked Example: Khalti’s 2FA Khalti uses:
- Knowledge: Your phone PIN.
- Possession: Your registered SIM (for OTP).
- Inherence: Fingerprint (on newer devices). Attack scenario: If an attacker steals your phone, they’d still need your fingerprint to bypass Khalti’s login.
Authentication Methods in Depth
1. Password-Based Authentication
How it works:
- User enters a secret (password) → system checks against a stored hash (never the plaintext).
- Salting: Adds random data to hashes to prevent rainbow-table attacks.
sequenceDiagram
User->>Server: Enter "password123"
Server->>Database: Check hash("password123" + salt)
Database-->>Server: Match? Yes/No
Server-->>User: Access Granted/DeniedReal-World Use:
- eSewa: Stores password hashes with bcrypt (a slow-hashing algorithm to thwart brute-force attacks).
- Ncell MyAccount: Requires passwords + OTP for sensitive actions (e.g., changing SIM details).
Weaknesses:
- Brute-force attacks: Trying all possible combinations (mitigated by rate-limiting).
- Phishing: Tricking users into entering passwords on fake sites (e.g., "Nepal Police" scams).
2. Token-Based Authentication
Types:
- Hardware Tokens: Physical devices (e.g., YubiKey) that generate one-time passwords (OTP).
- Software Tokens: Apps like Google Authenticator or SMS OTPs (e.g., Daraz’s order confirmations).
Example: Bank ATM Cards
Why it’s secure:
- Even if a card is stolen, the PIN (something you know) is needed.
- Chip-and-PIN (EMV) adds a cryptographic layer to prevent skimming.
Nepal Example:
- NMB Bank: Uses tokenized cards where the actual card number isn’t stored on the magnetic stripe (reduces skimming risk).
3. Biometric Authentication
Methods:
- Fingerprint: Used in smartphones (e.g., Pathao driver verification).
- Facial Recognition: Nepal Police uses it for ID verification.
- Iris/Retina Scan: High-security systems (e.g., military bases).
How it works:
- Enrollment: System scans and stores a template (not the full image).
- Authentication: Compares live scan to template using algorithms (e.g., minutiae matching for fingerprints).
Real Picture:
Limitations:
- Spoofing: Fake fingerprints (e.g., gelatin molds) can bypass weak systems.
- False Rejects: Dirty fingers or injuries may lock users out.
4. Multi-Factor Authentication (MFA)
Definition: Requires two or more factors for access. Example: NEPSE Trading Account
- Factor 1: Username + password (knowledge).
- Factor 2: OTP sent to registered phone (possession).
- Factor 3: Fingerprint (inherence, on mobile app).
Why MFA?
- Reduces risk of credential theft. Even if passwords are leaked (e.g., in a data breach), attackers need the second factor.
Nepal Case Study: Daraz Seller Accounts
- Attack: Hackers buy Daraz gift cards, then try to sell them via stolen seller accounts.
- Solution: Daraz now enforces MFA (email + OTP) for high-value transactions.
Access Control Models
Access control defines what authenticated users can do. Four key models:
| Model | Description | Example in Nepal |
|---|---|---|
| Discretionary (DAC) | Owner decides who gets access (e.g., file permissions in Windows). | A company’s shared Google Drive folder. |
| Mandatory (MAC) | Access granted by system admins based on security labels (e.g., military). | Nepal Army’s classified documents. |
| Role-Based (RBAC) | Permissions tied to job roles (e.g., "Manager" can approve loans). | NMB Bank: Tellers can’t process loans. |
| Rule-Based | Access granted based on predefined rules (e.g., time/location). | NTC: Only technicians can access network cores after 5 PM. |
Worked Example: RBAC in a Hospital (Kathmandu Medical College)
- Doctor: Can prescribe medicines and view records.
- Nurse: Can only view records and administer care.
- Admin: Can modify roles and audit logs.
Common Attacks on Authentication & Access Control
| Attack | How It Works | Nepal Example |
|---|---|---|
| Brute Force | Trying all password combinations (e.g., "admin:admin"). | Weak Wi-Fi passwords in guesthouses. |
| Phishing | Tricking users into revealing credentials (e.g., fake "Ncell bill payment" links). | 2022 scam targeting eSewa users. |
| Credential Stuffing | Using leaked passwords (from other sites) to hack accounts. | Daraz sellers hit after LinkedIn breaches. |
| Man-in-the-Middle (MITM) | Intercepting communications (e.g., unsecured Wi-Fi). | Public hotspots in Thamel used for fraud. |
| Privilege Escalation | Exploiting weak access controls to gain higher permissions. | Hackers accessing NTC’s billing system. |
Real-World Trace: Kathmandu Traffic Police System Hack (2023)
- Attackers phished a low-level employee’s credentials.
- Used privilege escalation to access the traffic fine database.
- Modified records to clear fines for fake vehicles. Lesson: Least-privilege access control would have limited the damage.
Security Policies for Authentication
1. Password Policies
- Complexity: Minimum 12 characters, mix of uppercase, numbers, symbols.
- Expiry: Rotate passwords every 90 days (controversial but common in banks).
- Reuse: Ban passwords used in previous roles (e.g., don’t reuse your old college email password for a bank).
Nepal Bank Example:
- Global IME Bank: Enforces 16-character passwords + 3 failed-attempt lockouts.
2. Least Privilege Principle
Definition: Users get only the access they need to do their job. Example:
- A call center agent at Ncell can reset passwords but cannot change SIM plans.
- A teacher at TU can grade exams but cannot delete student records.
3. Separation of Duties (SoD)
Definition: Critical tasks require multiple people to prevent fraud. Example:
- NMB Bank Loan Approval:
- Step 1: Officer reviews credit score.
- Step 2: Manager approves the loan.
- Step 3: Auditor verifies the transaction.
In the Real World
eSewa’s Two-Factor Authentication
- Idea Used: Multi-factor authentication (MFA) with OTP + biometrics.
- How It Works:
- User enters password → receives OTP on phone → scans fingerprint on mobile.
- Why It Matters: Even if a hacker steals your eSewa password, they’d need your phone and fingerprint to transfer money.
Khalti’s Fraud Detection with Behavioral Biometrics
- Idea Used: Continuous authentication (watching how users type/swipe).
- Example:
- If a user suddenly types too fast (bot) or from a new location (compromised device), Khalti blocks the transaction.
- Real Impact: Reduced fraudulent transactions by 40% in 2023.
Nepal Police’s Aadhaar Integration for Access Control
- Idea Used: Centralized identity verification via Aadhaar.
- How It Works:
- Police officers log in using Aadhaar OTP + fingerprint.
- Access to sensitive databases (e.g., criminal records) is logged and audited.
- Challenge: Rural areas with poor internet face delays, but urban stations use it for real-time verification.
Exam Tip
What Examiners Love to Test
Distinguish Authentication vs. Authorization
- Example Question: "Why does a bank employee need both a password (authentication) and a role like ‘Loan Officer’ (authorization)?"
- Your Answer: Authentication proves identity; authorization defines what that identity can do.
MFA Scenarios
- Example: "How would you secure a Daraz seller account against credential stuffing?"
- Your Answer:
- Factor 1: Password + 2FA (SMS/email OTP).
- Factor 2: Device fingerprinting (only allows logins from registered devices).
- Factor 3: Behavioral biometrics (blocks logins with unusual typing speed).
Access Control Models
- Example: "Compare RBAC and DAC. Which would you use for a university’s exam grading system?"
- Your Answer:
Model Exam System Fit Why? RBAC ✅ Best choice Professors, TAs, and admins have defined roles (e.g., "TA can grade but not modify questions"). DAC ❌ Risky If a professor shares their grading access with an untrusted TA, all exams could be tampered with.
Attack Responses
- Example: "A hacker uses a keylogger to steal a Pathao driver’s password. How would MFA stop this?"
- Your Answer:
- Even if the password is stolen, the hacker would also need:
- OTP (sent to the driver’s phone).
- Fingerprint (required for the Pathao app).
- Bonus: Pathao’s geofencing (only allows logins near the driver’s usual route) adds another layer.
- Even if the password is stolen, the hacker would also need:
Real-World Policy Questions
- Example: "Why does NTC enforce ‘least privilege’ for its network technicians?"
- Your Answer:
- Limits damage if an account is compromised.
- Example: A hacked technician cannot modify billing records (only access is to specific switches).
- Complies with Nepal’s IT Act 2006 (Section 28: "Access shall be granted on need-to-know basis").
Common Pitfalls to Avoid
- Mixing up factors: Don’t say a password is "something you have" (it’s knowledge).
- Ignoring real-world context: Always tie answers to Nepal (e.g., "Ncell uses OTPs because...").
- Overcomplicating: Examiners prefer clear, structured answers over jargon.
Quick Revision Checklist
Before the exam, ensure you can: ✅ Define authentication vs. authorization with examples. ✅ List three authentication factors and give a Nepal-based example for each. ✅ Draw a sequence diagram for password authentication (hashing + salt). ✅ Explain RBAC using a bank or hospital scenario. ✅ Name two attacks on authentication and how MFA stops them. ✅ Describe least privilege and separation of duties with a local example (e.g., NMB Bank).
Based on the TU BITM syllabus for Information Security (IT244), unit 7.
Discussion
Loading…