IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 512 min read

Authentication & Access Control: Methods, Models & Real-World Security

Unit 5 of Computer Security and Cyber Law covers authentication mechanisms (biometrics, tokens, passwords), access control models (MAC, DAC, RBAC), multi-factor authentication (MFA), and real-world applications like eSewa’s login systems and bank transaction authorizations. Learn how to design secure systems, analyze v

TAKEAWAYS:

  • Authentication verifies who you are (something you know/have/are), while access control defines what you can do (permissions, policies, and enforcement).
  • Multi-Factor Authentication (MFA) combines ≥2 factors (e.g., password + OTP + fingerprint) to thwart credential theft—used by Khalti and Ncell for high-value transactions.
  • Access control models (MAC/DAC/RBAC) determine how permissions are assigned: military-grade secrecy (MAC), user ownership (DAC), or role-based efficiency (RBAC).
  • Biometric systems (fingerprint, iris, facial recognition) balance convenience and security but face challenges like spoofing and privacy laws (e.g., Nepal’s Data Privacy Act 2075).
  • Single Sign-On (SSO) simplifies access across systems (e.g., TU’s student portal) but creates a single point of failure—if compromised, all linked accounts are at risk.
  • Least privilege and separation of duties are core principles to minimize damage from insider threats (e.g., a Daraz employee with full database access could manipulate orders).

1. Authentication: Proving Your Identity

Authentication is the first line of defense—it confirms that a user or system is who they claim to be. Without it, access control is meaningless. The three authentication factors form the CIA triad of authentication:

PasswordsPINsSecurity QuestionsSomething You KnowSmart CardsOTP Tokens (e.g., Google Authenticator)Hardware Keys (YubiKey)Something You HaveBiometrics: Fingerprint, Iris, Facial RecognitionBehavioral Biometrics (Typing rhythm, mouse movements)Something You AreAuthentication Factors
CIA triad of authentication factors with real-world examples
  • Problems:
    • Brute force attacks: Cracking weak passwords (e.g., "123456") in seconds using GPUs.
    • Phishing: Tricking users into revealing passwords (e.g., fake eSewa login pages).
    • Reuse: 65% of Nepalis reuse passwords across sites (Khalti breach 2021).
  • Solutions:
    • Password policies: Enforce 12+ characters, no dictionary words, and forced rotation.
    • Password managers: Tools like Bitwarden or KeePass generate and store unique passwords.
    • Proactive password checkers: Block common passwords (e.g., "password123") during registration.

Worked Example: eSewa’s Password Policy eSewa requires:

  • Minimum 8 characters, 1 uppercase, 1 number, 1 special character.
  • No reuse of last 5 passwords.
  • Why? To prevent brute-force attacks on user accounts (which could lead to fund theft).

1.2 Multi-Factor Authentication (MFA): Defense in Depth

MFA requires two or more factors to authenticate. It’s used by:

  • Banks: NMB Bank’s app requires OTP + fingerprint.
  • E-commerce: Daraz’s checkout uses password + email OTP.
  • Government: TU’s student portal uses username + password + OTP.
Step 1Enter Password(Something You Know)Step 2Scan Fingerprint(Something You Are)Step 3Insert OTP Token(Something You Have)Step 4Access Granted
MFA workflow showing layered authentication
Factor Example Security Level Convenience
Something You Know Password, PIN Low High
Something You Have OTP Token, Smart Card Medium Medium
Something You Are Fingerprint, Iris Scan High Low

Advantages of MFA:

  • Reduces credential theft success rate by 99.9% (Microsoft 2021).
  • Mitigates risks from phishing (even if password is stolen, attacker lacks the second factor).

Disadvantages:

  • User fatigue: Complex MFA can frustrate customers (e.g., Pathao drivers complaining about OTP delays).
  • Cost: Hardware tokens (e.g., YubiKey) add expense.

1.3 Biometric Authentication: Unique You

Biometrics use physical or behavioral traits that are hard to replicate. Common types:

pie
  title Biometric Modalities in Use Today
  "Fingerprint" : 45
  "Facial Recognition" : 30
  "Iris/Retina Scan" : 15
  "Voice Recognition" : 5
  "Behavioral (Typing)" : 5

Challenges:

  • Spoofing: Fake fingerprints (e.g., silicone replicas) can fool low-end scanners.
  • Privacy concerns: Nepal’s Data Privacy Act 2075 restricts biometric data collection without consent.
  • False rejects: Dirty fingers or injuries can lock users out (e.g., Ncell’s SIM registration failures).

Real-World Use:

  • Nepal Police: Use fingerprint scanners to verify criminal records.
  • Khalti: Offers facial recognition for high-value transactions (e.g., ₹50,000+).

2. Access Control: Who Gets In?

Once authenticated, access control determines what a user can do. Three core models:

2.1 Mandatory Access Control (MAC)

  • Definition: Access is assigned by a central authority (e.g., government, military) based on security clearance levels.
  • Example: Nepal Army’s classified documents (Top Secret > Secret > Confidential).
  • How it works:
    • Users get labels (e.g., "Clearance Level 3").
    • Objects (files, folders) have classifications.
    • Access is granted only if the user’s clearance dominates the object’s classification.
Top Secret (Clearance: Level 5)Secret (Clearance: Level 4)Confidential (Clearance: Level 3)Unclassified (Clearance: Level 2)MAC Hierarchy
Example MAC classification levels in government systems

Advantages:

  • Strict security: Prevents unauthorized access even by high-level users.
  • Centralized management: Easy to enforce policies (e.g., NTC’s network access rules).

Disadvantages:

  • Rigid: Users can’t share data freely (e.g., a TU professor can’t email a student classified files).
  • Complex: Requires constant label updates.

2.2 Discretionary Access Control (DAC)

  • Definition: Owners of resources (files, folders) decide who gets access.
  • Example: Your Google Drive files—you can share a folder with anyone.
  • How it works:
    • Access Control Lists (ACLs): Lists of users/permissions (e.g., "User A: Read/Write").
    • Permissions: Read, Write, Execute, Delete.
User Read Write Execute
Owner ✅ ✅ ✅
Group ✅ ❌ ❌
Others ❌ ❌ ❌

Advantages:

  • Flexible: Users control their own data (e.g., a Daraz seller managing product listings).
  • Simple: Easy to implement (used in Windows, Linux).

Disadvantages:

  • Security risks: Owners may grant access to unauthorized users (e.g., a TU student sharing exam papers).
  • No central oversight: Hard to audit (e.g., NEPSE insider trading risks).

Worked Example: TU Student Portal

  • DAC in action: A student can only access their own grades, not others’.
  • Risk: If a student’s account is compromised, their grades could be tampered with.

2.3 Role-Based Access Control (RBAC)

  • Definition: Access is granted based on roles (e.g., "Admin," "Cashier," "Guest").
  • Example: A bank’s RBAC system:
    • Teller: Can process transactions but not view accounts.
    • Manager: Can approve loans and view all accounts.

Advantages:

  • Scalable: Easy to manage for large organizations (e.g., Ncell’s 10M+ users).
  • Least privilege: Users get only the permissions needed for their role.
  • Audit-friendly: Logs show who did what based on their role.

Disadvantages:

  • Role explosion: Too many roles can become unmanageable (e.g., a company with 50+ roles).
  • Role creep: Employees retain access after role changes (e.g., a fired Daraz employee still has admin rights).

Worked Example: NMB Bank’s RBAC

  • Cashier Role: Can process withdrawals but not transfer funds.
  • Branch Manager Role: Can approve loans and override cashier actions.
  • Audit Trail: Logs show who approved a ₹500,000 loan.

3. Authentication and Access Control in Action

3.1 Single Sign-On (SSO): Convenience vs. Risk

  • How it works:
    1. User logs into Identity Provider (IdP) (e.g., TU portal).
    2. IdP issues a token (JWT) for other services.
    3. Services trust the token and grant access.
  • Used by:
    • Google: Sign in with Google to access YouTube, Drive, etc.
    • eSewa: SSO for linked bank accounts.
  • Risks:
    • Single point of failure: Compromise the IdP, and all linked accounts are at risk (e.g., LinkedIn breach 2016).
    • Phishing: Fake SSO pages steal credentials (e.g., fake TU portal).

Mitigation:

  • Use MFA for SSO (e.g., TU requires OTP for SSO login).
  • Short-lived tokens: Tokens expire after 1 hour (e.g., Ncell’s session tokens).

3.2 Denial of Service (DoS) and Authentication

While not strictly access control, DoS attacks can bypass authentication by overwhelming systems.

Example: Credential Stuffing Attack on Khalti

  1. Attacker uses a list of leaked passwords (from other breaches).
  2. Automated bots try these passwords on Khalti accounts.
  3. Even if Khalti has strong passwords, reused credentials get cracked.

Solution:

  • Rate limiting: Block repeated login attempts (e.g., Ncell locks accounts after 5 failed PIN tries).
  • CAPTCHA: Slow down automated attacks (e.g., Google’s reCAPTCHA).

4.1 Nepal’s Cyber Security Act 2075

  • Authentication requirements: Government systems must use MFA and biometrics where possible.
  • Access logs: Organizations must maintain audit logs for 1 year (e.g., NTC’s network access logs).
  • Penalties: Unauthorized access can lead to 3 years in prison + ₹500,000 fine.

4.2 Ethical Issues

  • Privacy vs. Security: Biometric data collection (e.g., Ncell’s SIM registration) raises privacy concerns.
  • Insider threats: Employees with excessive access (e.g., a Daraz admin manipulating orders).
  • Social engineering: Tricking users into revealing credentials (e.g., "Your account is locked—call this number").

In the Real World

  1. Khalti’s MFA for High-Value Transactions

    • Idea: Multi-Factor Authentication (password + OTP + fingerprint).
    • How it works: For transactions over ₹50,000, Khalti requires three factors to prevent fraud.
    • Impact: Reduced fraud cases by 80% since 2021 (Khalti Annual Report).
  2. Ncell’s SIM Registration Biometrics

    • Idea: Biometric authentication (fingerprint + face scan).
    • How it works: New SIM buyers must submit fingerprint and face ID to prevent duplicate SIMs (used for scams).
    • Impact: Cracked down on SIM-based fraud (e.g., fake identities for loans).
  3. TU’s Student Portal RBAC

    • Idea: Role-Based Access Control.
    • How it works:
      • Student: Can view grades, register courses.
      • Professor: Can upload syllabi, grade exams.
      • Admin: Can reset passwords, ban accounts.
    • Impact: Prevents students from accessing other students’ records.
  4. NMB Bank’s Loan Approval Workflow

    • Idea: DAC + RBAC.
    • How it works:
      • Customer: Submits loan application (DAC: only they can edit).
      • Teller: Reviews documents (RBAC: can’t approve loans).
      • Manager: Approves/rejects (RBAC: full authority).
    • Impact: Reduces insider fraud (e.g., tellers approving fake loans).

Exam Tip

This unit is heavily tested on:

  1. Definitions: Know the exact differences between MAC, DAC, and RBAC (e.g., "MAC uses labels, DAC uses ACLs").
  2. Real-world examples: Be ready to explain how Khalti, Ncell, or TU implement authentication/access control.
  3. Diagrams: Draw ACL tables, RBAC hierarchies, and MFA flows in exams.
  4. Legal frameworks: Nepal’s Cyber Security Act 2075 and Data Privacy Act 2075 often appear in short-answer questions.
  5. Weaknesses: For each method (e.g., passwords, biometrics, SSO), list 2-3 vulnerabilities (e.g., "passwords are vulnerable to phishing and brute force").

Common Past Exam Questions:

  • Compare MAC and DAC (table format).
  • Explain how RBAC works in a bank (use roles like Teller, Manager).
  • Describe two-factor authentication with an example from eSewa or Ncell.
  • What are the ethical concerns of biometric authentication in Nepal?

Pro Tip: Memorize the CIA triad of authentication (Confidentiality, Integrity, Availability) and how each model (MAC/DAC/RBAC) affects it. For example:

  • MAC → High confidentiality (military-grade).
  • DAC → High availability (users control access).
  • RBAC → Balances integrity (roles limit actions).

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 5.

Discussion

Loading…