Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.3
Related:
Clause 5
|
5.2 Password authentication
|
FR 1
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device
The verifier issues a one-time challenge (nonce). The claimant returns a response computed from the challenge and a shared secret, so the password itself is not sent. CHAP-class protocols are the usual IT example.
Replay and interception of reusable passwords on the wire. Stronger than sending even encrypted static passwords across a network.
Remote user or device login to a network access server, VPN concentrator or similar. Each party must share (or derive) the secret and the algorithm.
Managing master algorithms and master secrets becomes harder as more parties join. Compromise of the master secret collapses the scheme. Not all IACS devices implement it.
Prefer for network user authentication over reusable passwords. Device-to-device use is limited by protocol support (see 5.9).