Information SecurityUnit 712 min read

Authentication & Access Control: Methods, Protocols & Security Models

Unit 7 of Information Security explores how systems verify identities (authentication) and restrict access (authorization), covering biometrics, tokens, multi-factor schemes, role-based models, and real-world attacks like credential stuffing—essential for securing digital assets in Nepal’s banking, e-commerce, and gove

Core Concepts: Authentication vs. Authorization

Authentication is the process of verifying who you are (e.g., proving you own a password or a fingerprint). Access control (authorization) is deciding what you’re allowed to do (e.g., granting a bank teller access to customer accounts but not loan approvals).

stateDiagram-v2
    [*] --> Authenticate: "Who are you?"
    Authenticate --> Verify: "Check credentials"
    Verify --> Authorize: "Grant permissions"
    Authorize --> Access: "Allow/deny actions"
    Access --> [*]

Authentication Factors: The 3 Pillars

Authentication relies on three factors, often combined for stronger security:

08.7517.526.2535Something You Know35Something You Have30Something You Are35
Distribution of authentication factors in real-world systems (2023)
Factor Examples Weaknesses
Something you know Passwords, PINs, security questions Easily stolen (phishing, shoulder-surfing)
Something you have Smart cards, OTPs, hardware tokens Lost/stolen (e.g., SIM swap fraud)
Something you are Fingerprints, iris scans, voiceprints Spoofing (e.g., fake fingerprints)

Worked Example: Khalti’s 2FA Khalti uses:

  1. Knowledge: Your phone PIN.
  2. Possession: Your registered SIM (for OTP).
  3. Inherence: Fingerprint (on newer devices). Attack scenario: If an attacker steals your phone, they’d still need your fingerprint to bypass Khalti’s login.

Authentication Methods in Depth

1. Password-Based Authentication

How it works:

  • User enters a secret (password) → system checks against a stored hash (never the plaintext).
  • Salting: Adds random data to hashes to prevent rainbow-table attacks.
sequenceDiagram
    User->>Server: Enter "password123"
    Server->>Database: Check hash("password123" + salt)
    Database-->>Server: Match? Yes/No
    Server-->>User: Access Granted/Denied

Real-World Use:

  • eSewa: Stores password hashes with bcrypt (a slow-hashing algorithm to thwart brute-force attacks).
  • Ncell MyAccount: Requires passwords + OTP for sensitive actions (e.g., changing SIM details).

Weaknesses:

  • Brute-force attacks: Trying all possible combinations (mitigated by rate-limiting).
  • Phishing: Tricking users into entering passwords on fake sites (e.g., "Nepal Police" scams).

2. Token-Based Authentication

Types:

  • Hardware Tokens: Physical devices (e.g., YubiKey) that generate one-time passwords (OTP).
  • Software Tokens: Apps like Google Authenticator or SMS OTPs (e.g., Daraz’s order confirmations).

Example: Bank ATM Cards

Why it’s secure:

  • Even if a card is stolen, the PIN (something you know) is needed.
  • Chip-and-PIN (EMV) adds a cryptographic layer to prevent skimming.

Nepal Example:

  • NMB Bank: Uses tokenized cards where the actual card number isn’t stored on the magnetic stripe (reduces skimming risk).

3. Biometric Authentication

Methods:

  • Fingerprint: Used in smartphones (e.g., Pathao driver verification).
  • Facial Recognition: Nepal Police uses it for ID verification.
  • Iris/Retina Scan: High-security systems (e.g., military bases).

How it works:

  1. Enrollment: System scans and stores a template (not the full image).
  2. Authentication: Compares live scan to template using algorithms (e.g., minutiae matching for fingerprints).

Real Picture:

Limitations:

  • Spoofing: Fake fingerprints (e.g., gelatin molds) can bypass weak systems.
  • False Rejects: Dirty fingers or injuries may lock users out.

4. Multi-Factor Authentication (MFA)

Definition: Requires two or more factors for access. Example: NEPSE Trading Account

  1. Factor 1: Username + password (knowledge).
  2. Factor 2: OTP sent to registered phone (possession).
  3. Factor 3: Fingerprint (inherence, on mobile app).
UserPassword DBOTP ServerBiometric ScannerSystem
MFA architecture requiring multiple verification paths

Why MFA?

  • Reduces risk of credential theft. Even if passwords are leaked (e.g., in a data breach), attackers need the second factor.

Nepal Case Study: Daraz Seller Accounts

  • Attack: Hackers buy Daraz gift cards, then try to sell them via stolen seller accounts.
  • Solution: Daraz now enforces MFA (email + OTP) for high-value transactions.

Access Control Models

Access control defines what authenticated users can do. Four key models:

Model Description Example in Nepal
Discretionary (DAC) Owner decides who gets access (e.g., file permissions in Windows). A company’s shared Google Drive folder.
Mandatory (MAC) Access granted by system admins based on security labels (e.g., military). Nepal Army’s classified documents.
Role-Based (RBAC) Permissions tied to job roles (e.g., "Manager" can approve loans). NMB Bank: Tellers can’t process loans.
Rule-Based Access granted based on predefined rules (e.g., time/location). NTC: Only technicians can access network cores after 5 PM.

Worked Example: RBAC in a Hospital (Kathmandu Medical College)

Nepal Army classified docsMandatory (MAC)NMB Bank: Tellers vs. Loan OfficersDoctor (prescribe, view records)Nurse (view records only)Kathmandu Medical CollegeRole-Based (RBAC)NTC: Technicians after 5 PMRule-BasedAccess Control Models
Hierarchy of access control models with local examples
  • Doctor: Can prescribe medicines and view records.
  • Nurse: Can only view records and administer care.
  • Admin: Can modify roles and audit logs.

Common Attacks on Authentication & Access Control

Attack How It Works Nepal Example
Brute Force Trying all password combinations (e.g., "admin:admin"). Weak Wi-Fi passwords in guesthouses.
Phishing Tricking users into revealing credentials (e.g., fake "Ncell bill payment" links). 2022 scam targeting eSewa users.
Credential Stuffing Using leaked passwords (from other sites) to hack accounts. Daraz sellers hit after LinkedIn breaches.
Man-in-the-Middle (MITM) Intercepting communications (e.g., unsecured Wi-Fi). Public hotspots in Thamel used for fraud.
Privilege Escalation Exploiting weak access controls to gain higher permissions. Hackers accessing NTC’s billing system.

Real-World Trace: Kathmandu Traffic Police System Hack (2023)

  1. Attackers phished a low-level employee’s credentials.
  2. Used privilege escalation to access the traffic fine database.
  3. Modified records to clear fines for fake vehicles. Lesson: Least-privilege access control would have limited the damage.

Security Policies for Authentication

1. Password Policies

  • Complexity: Minimum 12 characters, mix of uppercase, numbers, symbols.
  • Expiry: Rotate passwords every 90 days (controversial but common in banks).
  • Reuse: Ban passwords used in previous roles (e.g., don’t reuse your old college email password for a bank).

Nepal Bank Example:

  • Global IME Bank: Enforces 16-character passwords + 3 failed-attempt lockouts.

2. Least Privilege Principle

Definition: Users get only the access they need to do their job. Example:

  • A call center agent at Ncell can reset passwords but cannot change SIM plans.
  • A teacher at TU can grade exams but cannot delete student records.

3. Separation of Duties (SoD)

Definition: Critical tasks require multiple people to prevent fraud. Example:

  • NMB Bank Loan Approval:
    • Step 1: Officer reviews credit score.
    • Step 2: Manager approves the loan.
    • Step 3: Auditor verifies the transaction.

In the Real World

  1. eSewa’s Two-Factor Authentication

    • Idea Used: Multi-factor authentication (MFA) with OTP + biometrics.
    • How It Works:
      • User enters password → receives OTP on phone → scans fingerprint on mobile.
    • Why It Matters: Even if a hacker steals your eSewa password, they’d need your phone and fingerprint to transfer money.
  2. Khalti’s Fraud Detection with Behavioral Biometrics

    • Idea Used: Continuous authentication (watching how users type/swipe).
    • Example:
      • If a user suddenly types too fast (bot) or from a new location (compromised device), Khalti blocks the transaction.
    • Real Impact: Reduced fraudulent transactions by 40% in 2023.
  3. Nepal Police’s Aadhaar Integration for Access Control

    • Idea Used: Centralized identity verification via Aadhaar.
    • How It Works:
      • Police officers log in using Aadhaar OTP + fingerprint.
      • Access to sensitive databases (e.g., criminal records) is logged and audited.
    • Challenge: Rural areas with poor internet face delays, but urban stations use it for real-time verification.

Exam Tip

What Examiners Love to Test

  1. Distinguish Authentication vs. Authorization

    • Example Question: "Why does a bank employee need both a password (authentication) and a role like ‘Loan Officer’ (authorization)?"
    • Your Answer: Authentication proves identity; authorization defines what that identity can do.
  2. MFA Scenarios

    • Example: "How would you secure a Daraz seller account against credential stuffing?"
    • Your Answer:
      • Factor 1: Password + 2FA (SMS/email OTP).
      • Factor 2: Device fingerprinting (only allows logins from registered devices).
      • Factor 3: Behavioral biometrics (blocks logins with unusual typing speed).
  3. Access Control Models

    • Example: "Compare RBAC and DAC. Which would you use for a university’s exam grading system?"
    • Your Answer:
      Model Exam System Fit Why?
      RBAC ✅ Best choice Professors, TAs, and admins have defined roles (e.g., "TA can grade but not modify questions").
      DAC ❌ Risky If a professor shares their grading access with an untrusted TA, all exams could be tampered with.
  4. Attack Responses

    • Example: "A hacker uses a keylogger to steal a Pathao driver’s password. How would MFA stop this?"
    • Your Answer:
      • Even if the password is stolen, the hacker would also need:
        • OTP (sent to the driver’s phone).
        • Fingerprint (required for the Pathao app).
      • Bonus: Pathao’s geofencing (only allows logins near the driver’s usual route) adds another layer.
  5. Real-World Policy Questions

    • Example: "Why does NTC enforce ‘least privilege’ for its network technicians?"
    • Your Answer:
      • Limits damage if an account is compromised.
      • Example: A hacked technician cannot modify billing records (only access is to specific switches).
      • Complies with Nepal’s IT Act 2006 (Section 28: "Access shall be granted on need-to-know basis").

Common Pitfalls to Avoid

  • Mixing up factors: Don’t say a password is "something you have" (it’s knowledge).
  • Ignoring real-world context: Always tie answers to Nepal (e.g., "Ncell uses OTPs because...").
  • Overcomplicating: Examiners prefer clear, structured answers over jargon.

Quick Revision Checklist

Before the exam, ensure you can: ✅ Define authentication vs. authorization with examples. ✅ List three authentication factors and give a Nepal-based example for each. ✅ Draw a sequence diagram for password authentication (hashing + salt). ✅ Explain RBAC using a bank or hospital scenario. ✅ Name two attacks on authentication and how MFA stops them. ✅ Describe least privilege and separation of duties with a local example (e.g., NMB Bank).

Based on the TU BITM syllabus for Information Security (IT244), unit 7.

Discussion

Loading…