← Home

IEC 62443-3-1 Clause 5.3 – Challenge/Response Authentication

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.3
Related: Clause 5 | 5.2 Password authentication | FR 1

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device


What it is

The verifier issues a one-time challenge (nonce). The claimant returns a response computed from the challenge and a shared secret, so the password itself is not sent. CHAP-class protocols are the usual IT example.


Vulnerabilities addressed

Replay and interception of reusable passwords on the wire. Stronger than sending even encrypted static passwords across a network.


Typical deployment

Remote user or device login to a network access server, VPN concentrator or similar. Each party must share (or derive) the secret and the algorithm.


Known issues and weaknesses

Managing master algorithms and master secrets becomes harder as more parties join. Compromise of the master secret collapses the scheme. Not all IACS devices implement it.


Use in IACS

Prefer for network user authentication over reusable passwords. Device-to-device use is limited by protocol support (see 5.9).


Recommendations