SSCP Systems Security Certified PractitionerAccess ControlsHard
A security architect is designing an authentication system for a highly sensitive research facility. They require an authentication method that provides very high assurance of identity, is difficult to forge, and is resistant to replay attacks. Which authentication method, when properly implemented, would best meet these stringent requirements?
- AShared secret key with Kerberos authentication
- BStatic password with a complex policy
- CBiometric (e.g., fingerprint) with local database verification
- DOne-Time Password (OTP) generated by a hardware token
Show answer & explanationAnswer & explanation
Correct answer: A. Shared secret key with Kerberos authentication
Kerberos, using a shared secret key (password) and a ticket-granting system, is specifically designed to provide strong authentication in a distributed environment, offering resistance to replay attacks through the use of timestamps and session keys. It offers high assurance and is difficult to forge when properly implemented.
Why the other options are wrong
- B. Static passwords, even complex ones, are vulnerable to various attacks (e.g., brute-force, phishing) and do not inherently resist replay attacks.
- C. Biometrics offer 'something you are' but can have spoofing vulnerabilities, and 'local database verification' might not be 'very high assurance' or resistant to replay in a network context.
- D. OTPs from hardware tokens provide 'something you have' and are good against replay attacks, but the question asks for 'very high assurance' and 'difficult to forge' in a general sense, and Kerberos offers a more robust, integrated solution for distributed environments.
Kerberos Authentication Protocol
A network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner.
- Uses symmetric-key cryptography.
- Provides mutual authentication.
- Resistant to replay attacks through timestamps.
- Requires a Key Distribution Center (KDC).
Memory trick: Kerberos: The K-9 guard dog of network authentication.