Authentication Requirements: The Attacks on a Message
Chapter Forty-Two
Syllabus topic Module 1, "Message Authentication and Hash Functions: Authentication Requirements"
Pages 256 to 259 of 678
In one line
Eight things can go wrong with a message in transit, and message authentication answers six of them. Knowing which six, and which two need something else, is the whole of this topic.
In the wording a student can write in an examination: message authentication is the procedure by which communicating parties verify that received messages are authentic, meaning that the contents are unaltered, that the source is who it claims to be, and that the message is timely and in sequence. The requirements are best set out as the list of attacks that authentication must counter: disclosure, traffic analysis, masquerade, content modification, sequence modification, timing modification, source repudiation and destination repudiation.
The eight attacks
1. Disclosure. Releasing message contents to anybody not possessing the appropriate key. A student's marks read off the wire.
2. Traffic analysis. Discovering the pattern of traffic: the frequency and length of messages between parties, from which the nature of the communication may be inferred. Two hundred megabytes from the Examination Section to the printer at three in the morning in November.
3. Masquerade. Insertion of messages into the network from a fraudulent source. This includes the creation of messages by an opponent purporting to come from an authorised entity, and also fraudulent acknowledgements of receipt or non-receipt. A message in the Head of Department's name authorising a mark change.
4. Content modification. Changes to the contents of a message, including insertion, deletion, transposition and modification. An internal mark of 12 altered to 42.
5. Sequence modification. Any modification to a sequence of messages between parties, including insertion, deletion and reordering. The second instalment of a fee receipt delivered before the first, so that the running balance is wrong.
6. Timing modification. Delay or replay of messages. In a connection-oriented application an entire session or sequence of messages could be a replay of a previous valid sequence; or individual messages could be delayed or replayed. A fee payment authorisation held back for an hour and then sent four times.
7. Source repudiation. Denial of transmission of a message by the source. A department denying that it submitted the marks it submitted.
8. Destination repudiation. Denial of receipt of a message by the destination. The Examination Section denying that it received the marks the department sent.
Which service answers which, and the two that message authentication does not
| Attack | Answered by | Notes |
|---|---|---|
| 1. Disclosure | message encryption, not authentication | confidentiality is a different service |
| 2. Traffic analysis | traffic flow confidentiality: padding and routing control | not answered by authentication at all |
| 3. Masquerade | message authentication | the authenticator can only be made by a key holder |
| 4. Content modification | message authentication | the authenticator covers the contents |
| 5. Sequence modification | message authentication with a sequence number | the authenticator must cover the number |
| 6. Timing modification | message authentication with a timestamp or nonce | the authenticator must cover the time |
| 7. Source repudiation | digital signature, not a MAC | needs asymmetry; see the services chapter |
| 8. Destination repudiation | digital signature plus a protocol | the recipient must be made to produce a signed receipt |
Authentication Requirements: The Attacks on a Message
Read the table's shape. Items 1 and 2 are confidentiality problems, not authentication problems, and a question that asks "what does message authentication protect against" should exclude them and say why. Items 3 to 6 are what message authentication is for. Items 7 and 8 need a digital signature, because a shared-key authenticator can be produced by either party.
And notice items 5 and 6 carefully, because they are the ones students get wrong. A message authentication code over the contents alone does not stop reordering or replay: the replayed message is genuine and its tag is valid. The sequence number or the timestamp must be inside the data the authenticator covers, and that is a design requirement, not an optional extra.
Worked example: designing against all eight
The requirement. A department submits internal marks to the University, one message per student, over the campus network.
Attack 4, content modification. Compute a message authentication code over the whole message with a key shared with the University. An altered message fails the check.
Attack 3, masquerade. The same MAC answers it: only a holder of the key can produce a valid tag, so a message from a fraudulent source has no valid tag.
Attack 5, sequence modification. Number the messages 1 to N and include the number inside the data the MAC covers. A reordered or deleted message is now detectable, because the receiver expects number 7 and the tag on the message claiming to be 7 is a tag over 9.
Attack 6, timing modification. Include a timestamp, also inside the MAC's coverage, and reject a message whose timestamp is outside a window. Or use a nonce and remember the nonces seen in this session.
Attack 1, disclosure. Encrypt the message. The MAC does not hide anything, so this is a second, separate mechanism.
Attack 2, traffic analysis. Send a fixed number of messages of fixed length every day, padding with dummies. This is expensive, and most systems accept the exposure. Saying so is more honest than pretending padding is free.
Attacks 7 and 8, repudiation. Replace the MAC with a digital signature over each message, so the University can prove to a third party which department signed it. And require the University to return a signed receipt, so the department can prove delivery. Neither is achievable with the shared-key MAC, however strong.
Authentication Requirements: The Attacks on a Message
The step that carries the marks. Naming, for each attack, whether the answer is authentication, confidentiality, a sequence number, a timestamp, or a signature. A design that applies one MAC and claims to have answered all eight has answered four.
What beginners get wrong here
Thinking message authentication provides confidentiality. It does not. A MAC is appended to a message that is still readable.
Thinking a MAC stops replay. It does not, unless a sequence number or timestamp is inside its coverage. The replayed message is genuine and its tag is valid.
Putting the sequence number outside the authenticator. Then the attacker changes the number and the tag still verifies over the contents. Whatever must not be altered must be inside the coverage.
Claiming a MAC gives non-repudiation. It gives authentication between two parties who share a key, and nothing that can be shown to a third.
Omitting traffic analysis because it is inconvenient. It is one of the eight and the honest answer is that it costs padding and most systems decline to pay.
Quick revision
- Eight attacks: disclosure, traffic analysis, masquerade, content modification, sequence modification, timing modification, source repudiation, destination repudiation.
- 1 and 2 are confidentiality problems, answered by encryption and by traffic padding, not by authentication.
- 3 to 6 are what message authentication answers.
- 7 and 8 need a digital signature, because a shared key lets either party produce the authenticator.
- A MAC over the contents alone does not stop reordering or replay. The sequence number and the timestamp must be inside the data the authenticator covers.
- Authentication means: contents unaltered, source as claimed, and timely and in sequence.
Test yourself
1. List the eight attacks that message authentication must be considered against. Disclosure; traffic analysis; masquerade; content modification; sequence modification; timing modification; source repudiation; and destination repudiation.
2. Which two are not answered by message authentication, and what answers them? Disclosure and traffic analysis. Disclosure is answered by encryption, that is by the data confidentiality service. Traffic analysis is answered by traffic flow confidentiality, which requires traffic padding and routing control, because encryption leaves the pattern of messages visible.
3. Which two require a digital signature rather than a message authentication code? Source repudiation and destination repudiation. A message authentication code is computed with a key both parties hold, so either could have produced it and neither can prove the other's authorship to a third party. A digital signature made with a private key can be produced by only one party and verified by anybody.
4. Why does a message authentication code over the contents not prevent replay? Because a replayed message is a genuine message: its contents are unaltered and its tag is a valid tag over those contents. Nothing in the message distinguishes a first delivery from a second. Freshness must be supplied separately, by including a sequence number, a timestamp or a nonce in the data the authenticator covers.
Authentication Requirements: The Attacks on a Message
5. Why must a sequence number be inside the authenticator's coverage? Because if it is outside, an attacker can alter the number while leaving the contents and the tag unchanged, and the tag will still verify. Only data covered by the authenticator is protected, so anything that must not be altered, including sequence numbers and timestamps, must be part of what is authenticated.
6. Define message authentication. The procedure by which communicating parties verify that received messages are authentic: that the contents have not been altered, that the source is who it claims to be, and that the message is timely and in the correct sequence.
7. Give a college example of sequence modification and of timing modification. Sequence modification: the second instalment of a fee receipt is delivered before the first, so the running balance shown to the student is wrong. Timing modification: a fee payment authorisation is held back for an hour and then delivered four times, so the student is charged four times for one payment.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.