Challenge Handshake Authentication Protocol (CHAP)
A PPP authentication protocol (RFC 1994) where the server sends a random challenge and the client returns a hash of it with a shared secret, so the secret never crosses the link.
The Challenge Handshake Authentication Protocol, defined in RFC 1994, authenticates the peer on a Point-to-Point Protocol link. The authenticator sends a challenge containing a random value. The peer combines that value with an identifier and a secret both sides share, hashes the result with MD5, and returns the hash. The authenticator computes the same hash and compares. Because each challenge is new, a captured response is of no use later, which gives CHAP resistance to replay attacks, and the authenticator may repeat the challenge at intervals during the session.
CHAP is the answer to the obvious weakness of the Password Authentication Protocol (PAP), which sends the password in clear text. CHAP has weaknesses of its own. Both ends must hold the secret in a form that can be used to compute the hash, so the server’s copy is a sensitive target. A captured exchange lets an attacker test guesses offline against a weak secret. MD5 is no longer a strong hash. The Extensible Authentication Protocol later replaced fixed methods with a framework that carries many.
Exam relevance: questions in this area tend to rank remote access authentication protocols. Candidates are expected to place PAP (clear text) below CHAP (challenge and hash) and CHAP below the stronger EAP-based methods, and to recognise a challenge and response as the feature that defeats simple replay.