Computer Security and Cyber LawUnit 512 min read
Authentication & Access Control: Methods, Models & Real-World Security
Unit 5 of Computer Security and Cyber Law covers authentication mechanisms (biometrics, tokens, passwords), access control models (MAC, DAC, RBAC), multi-factor authentication (MFA), and real-world applications like eSewa’s login systems and bank transaction authorizations. Learn how to design secure systems, analyze v
TAKEAWAYS:
- Authentication verifies who you are (something you know/have/are), while access control defines what you can do (permissions, policies, and enforcement).
- Multi-Factor Authentication (MFA) combines ≥2 factors (e.g., password + OTP + fingerprint) to thwart credential theft—used by Khalti and Ncell for high-value transactions.
- Access control models (MAC/DAC/RBAC) determine how permissions are assigned: military-grade secrecy (MAC), user ownership (DAC), or role-based efficiency (RBAC).
- Biometric systems (fingerprint, iris, facial recognition) balance convenience and security but face challenges like spoofing and privacy laws (e.g., Nepal’s Data Privacy Act 2075).
- Single Sign-On (SSO) simplifies access across systems (e.g., TU’s student portal) but creates a single point of failure—if compromised, all linked accounts are at risk.
- Least privilege and separation of duties are core principles to minimize damage from insider threats (e.g., a Daraz employee with full database access could manipulate orders).
1. Authentication: Proving Your Identity
Authentication is the first line of defense—it confirms that a user or system is who they claim to be. Without it, access control is meaningless. The three authentication factors form the CIA triad of authentication:
1.1 Passwords: The Weakest Link?
- Problems:
- Brute force attacks: Cracking weak passwords (e.g., "123456") in seconds using GPUs.
- Phishing: Tricking users into revealing passwords (e.g., fake eSewa login pages).
- Reuse: 65% of Nepalis reuse passwords across sites (Khalti breach 2021).
- Solutions:
- Password policies: Enforce 12+ characters, no dictionary words, and forced rotation.
- Password managers: Tools like Bitwarden or KeePass generate and store unique passwords.
- Proactive password checkers: Block common passwords (e.g., "password123") during registration.
Worked Example: eSewa’s Password Policy eSewa requires:
- Minimum 8 characters, 1 uppercase, 1 number, 1 special character.
- No reuse of last 5 passwords.
- Why? To prevent brute-force attacks on user accounts (which could lead to fund theft).
1.2 Multi-Factor Authentication (MFA): Defense in Depth
MFA requires two or more factors to authenticate. It’s used by:
- Banks: NMB Bank’s app requires OTP + fingerprint.
- E-commerce: Daraz’s checkout uses password + email OTP.
- Government: TU’s student portal uses username + password + OTP.
| Factor | Example | Security Level | Convenience |
|---|---|---|---|
| Something You Know | Password, PIN | Low | High |
| Something You Have | OTP Token, Smart Card | Medium | Medium |
| Something You Are | Fingerprint, Iris Scan | High | Low |
Advantages of MFA:
- Reduces credential theft success rate by 99.9% (Microsoft 2021).
- Mitigates risks from phishing (even if password is stolen, attacker lacks the second factor).
Disadvantages:
- User fatigue: Complex MFA can frustrate customers (e.g., Pathao drivers complaining about OTP delays).
- Cost: Hardware tokens (e.g., YubiKey) add expense.
1.3 Biometric Authentication: Unique You
Biometrics use physical or behavioral traits that are hard to replicate. Common types:
pie title Biometric Modalities in Use Today "Fingerprint" : 45 "Facial Recognition" : 30 "Iris/Retina Scan" : 15 "Voice Recognition" : 5 "Behavioral (Typing)" : 5
Challenges:
- Spoofing: Fake fingerprints (e.g., silicone replicas) can fool low-end scanners.
- Privacy concerns: Nepal’s Data Privacy Act 2075 restricts biometric data collection without consent.
- False rejects: Dirty fingers or injuries can lock users out (e.g., Ncell’s SIM registration failures).
Real-World Use:
- Nepal Police: Use fingerprint scanners to verify criminal records.
- Khalti: Offers facial recognition for high-value transactions (e.g., ₹50,000+).
2. Access Control: Who Gets In?
Once authenticated, access control determines what a user can do. Three core models:
2.1 Mandatory Access Control (MAC)
- Definition: Access is assigned by a central authority (e.g., government, military) based on security clearance levels.
- Example: Nepal Army’s classified documents (Top Secret > Secret > Confidential).
- How it works:
- Users get labels (e.g., "Clearance Level 3").
- Objects (files, folders) have classifications.
- Access is granted only if the user’s clearance dominates the object’s classification.
Advantages:
- Strict security: Prevents unauthorized access even by high-level users.
- Centralized management: Easy to enforce policies (e.g., NTC’s network access rules).
Disadvantages:
- Rigid: Users can’t share data freely (e.g., a TU professor can’t email a student classified files).
- Complex: Requires constant label updates.
2.2 Discretionary Access Control (DAC)
- Definition: Owners of resources (files, folders) decide who gets access.
- Example: Your Google Drive files—you can share a folder with anyone.
- How it works:
- Access Control Lists (ACLs): Lists of users/permissions (e.g., "User A: Read/Write").
- Permissions: Read, Write, Execute, Delete.
| User | Read | Write | Execute |
|---|---|---|---|
| Owner | ✅ | ✅ | ✅ |
| Group | ✅ | ❌ | ❌ |
| Others | ❌ | ❌ | ❌ |
Advantages:
- Flexible: Users control their own data (e.g., a Daraz seller managing product listings).
- Simple: Easy to implement (used in Windows, Linux).
Disadvantages:
- Security risks: Owners may grant access to unauthorized users (e.g., a TU student sharing exam papers).
- No central oversight: Hard to audit (e.g., NEPSE insider trading risks).
Worked Example: TU Student Portal
- DAC in action: A student can only access their own grades, not others’.
- Risk: If a student’s account is compromised, their grades could be tampered with.
2.3 Role-Based Access Control (RBAC)
- Definition: Access is granted based on roles (e.g., "Admin," "Cashier," "Guest").
- Example: A bank’s RBAC system:
- Teller: Can process transactions but not view accounts.
- Manager: Can approve loans and view all accounts.
Advantages:
- Scalable: Easy to manage for large organizations (e.g., Ncell’s 10M+ users).
- Least privilege: Users get only the permissions needed for their role.
- Audit-friendly: Logs show who did what based on their role.
Disadvantages:
- Role explosion: Too many roles can become unmanageable (e.g., a company with 50+ roles).
- Role creep: Employees retain access after role changes (e.g., a fired Daraz employee still has admin rights).
Worked Example: NMB Bank’s RBAC
- Cashier Role: Can process withdrawals but not transfer funds.
- Branch Manager Role: Can approve loans and override cashier actions.
- Audit Trail: Logs show who approved a ₹500,000 loan.
3. Authentication and Access Control in Action
3.1 Single Sign-On (SSO): Convenience vs. Risk
- How it works:
- User logs into Identity Provider (IdP) (e.g., TU portal).
- IdP issues a token (JWT) for other services.
- Services trust the token and grant access.
- Used by:
- Google: Sign in with Google to access YouTube, Drive, etc.
- eSewa: SSO for linked bank accounts.
- Risks:
- Single point of failure: Compromise the IdP, and all linked accounts are at risk (e.g., LinkedIn breach 2016).
- Phishing: Fake SSO pages steal credentials (e.g., fake TU portal).
Mitigation:
- Use MFA for SSO (e.g., TU requires OTP for SSO login).
- Short-lived tokens: Tokens expire after 1 hour (e.g., Ncell’s session tokens).
3.2 Denial of Service (DoS) and Authentication
While not strictly access control, DoS attacks can bypass authentication by overwhelming systems.
Example: Credential Stuffing Attack on Khalti
- Attacker uses a list of leaked passwords (from other breaches).
- Automated bots try these passwords on Khalti accounts.
- Even if Khalti has strong passwords, reused credentials get cracked.
Solution:
- Rate limiting: Block repeated login attempts (e.g., Ncell locks accounts after 5 failed PIN tries).
- CAPTCHA: Slow down automated attacks (e.g., Google’s reCAPTCHA).
4. Legal and Ethical Considerations
4.1 Nepal’s Cyber Security Act 2075
- Authentication requirements: Government systems must use MFA and biometrics where possible.
- Access logs: Organizations must maintain audit logs for 1 year (e.g., NTC’s network access logs).
- Penalties: Unauthorized access can lead to 3 years in prison + ₹500,000 fine.
4.2 Ethical Issues
- Privacy vs. Security: Biometric data collection (e.g., Ncell’s SIM registration) raises privacy concerns.
- Insider threats: Employees with excessive access (e.g., a Daraz admin manipulating orders).
- Social engineering: Tricking users into revealing credentials (e.g., "Your account is locked—call this number").
In the Real World
Khalti’s MFA for High-Value Transactions
- Idea: Multi-Factor Authentication (password + OTP + fingerprint).
- How it works: For transactions over ₹50,000, Khalti requires three factors to prevent fraud.
- Impact: Reduced fraud cases by 80% since 2021 (Khalti Annual Report).
Ncell’s SIM Registration Biometrics
- Idea: Biometric authentication (fingerprint + face scan).
- How it works: New SIM buyers must submit fingerprint and face ID to prevent duplicate SIMs (used for scams).
- Impact: Cracked down on SIM-based fraud (e.g., fake identities for loans).
TU’s Student Portal RBAC
- Idea: Role-Based Access Control.
- How it works:
- Student: Can view grades, register courses.
- Professor: Can upload syllabi, grade exams.
- Admin: Can reset passwords, ban accounts.
- Impact: Prevents students from accessing other students’ records.
NMB Bank’s Loan Approval Workflow
- Idea: DAC + RBAC.
- How it works:
- Customer: Submits loan application (DAC: only they can edit).
- Teller: Reviews documents (RBAC: can’t approve loans).
- Manager: Approves/rejects (RBAC: full authority).
- Impact: Reduces insider fraud (e.g., tellers approving fake loans).
Exam Tip
This unit is heavily tested on:
- Definitions: Know the exact differences between MAC, DAC, and RBAC (e.g., "MAC uses labels, DAC uses ACLs").
- Real-world examples: Be ready to explain how Khalti, Ncell, or TU implement authentication/access control.
- Diagrams: Draw ACL tables, RBAC hierarchies, and MFA flows in exams.
- Legal frameworks: Nepal’s Cyber Security Act 2075 and Data Privacy Act 2075 often appear in short-answer questions.
- Weaknesses: For each method (e.g., passwords, biometrics, SSO), list 2-3 vulnerabilities (e.g., "passwords are vulnerable to phishing and brute force").
Common Past Exam Questions:
- Compare MAC and DAC (table format).
- Explain how RBAC works in a bank (use roles like Teller, Manager).
- Describe two-factor authentication with an example from eSewa or Ncell.
- What are the ethical concerns of biometric authentication in Nepal?
Pro Tip: Memorize the CIA triad of authentication (Confidentiality, Integrity, Availability) and how each model (MAC/DAC/RBAC) affects it. For example:
- MAC → High confidentiality (military-grade).
- DAC → High availability (users control access).
- RBAC → Balances integrity (roles limit actions).
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 5.
Discussion
Loading…