E Commerce Notes
E Commerce Notes
1
SYLLABUS
Unit-I
Electronic Commerce: Overview of Electronic Commerce, Scope of Electronic Commerce,
Traditional Commerce vs. Electronic Commerce, Impact of E-Commerce, Electronic Markets,
Internet Commerce, e-commerce in perspective, Application of E Commerce in Direct
Marketing and Selling, Obstacles in adopting E-Commerce Applications; Future of E-
Commerce.
Unit-II
Value Chains in electronic Commerce, Supply chain, Porter’s value chain Model, Inter
Organizational value chains, Strategic Business unit chains, Industry value chains.
Security Threats to E-commerce: Security Overview, Computer Security Classification,
Copyright and Intellectual Property, security Policy and Integrated Security, Intellectual
Property Threats, electronic Commerce Threats, Clients Threats, Communication Channel
Threats, server Threats.
Unit-III
Implementing security for E-Commerce: Protecting E-Commerce Assets, Protecting
Intellectual Property, Protecting Client Computers, Protecting E-commerce Channels,
Insuring Transaction Integrity, Protecting the Commerce Server. Electronic Payment System:
Electronic Cash, Electronic Wallets, Smart Card, Credit and Change Card.
Unit–IV
Business to Business E-Commerce: Inter-organizational Transitions, Credit Transaction
Trade Cycle, a variety of transactions. Electronic Data Interchange (EDI): Introduction to
EDI, Benefits of EDI, EDI Technology, EDI standards, EDI Communication, EDI
Implementation, EDI agreement, EDI security.
Suggested Readings:
1. [Link] and [Link],Readingsin Electronic Commerce, Addison Wesley,
2 David Kosiur, Understanding E- Commerce, Microsoft Press, 1997. 3) Soka,
From EDI to Electronic Commerce , McGraw Hill, 1995.
3 David whitely, E-commerce Strategy, Technology and application, Tata McGraw Hill.
4 Gary P. Schneider and Jame Perry, Electronic Commerce Thomson Publication. 5 Doing
Business on the Internet E-COMMERCE S. Jaiswal;Galgotia Publications.
6 E-Commerce An Indian Perspective; [Link]; S.J.; PHI.
7 E-Commerce; [Link] – Glgotia.
8 E-Commerce; Efrain Turbon; Jae Lee; David King; [Link] Chang.
2
Commerce refers to the exchange of goods and services between buyers and sellers. Over
time, this exchange has evolved from physical, face-to-face transactions (Traditional
Commerce) to digital, internet-based transactions (Electronic Commerce or E-Commerce).
Traditional commerce dominated business for centuries, but with the growth of the Internet
and digital technologies, E-Commerce has transformed how businesses operate globally.
3
Basis Traditional Commerce Electronic Commerce
Product Inspection Possible physically Only virtual viewing
Delivery Immediate Requires shipping
Advantages of E-Commerce
E-Commerce offers several benefits to both businesses and customers:
1. Global Reach
Businesses can sell products worldwide without physical expansion.
2. 24×7 Availability
Customers can shop anytime, increasing convenience and sales opportunities.
3. Lower Operating Costs
No need for expensive retail space; reduced manpower and inventory costs.
4. Easy Data Collection & Analysis
Customer behavior can be tracked for better marketing and decision-making.
5. Wide Product Choice
Customers can compare prices and products across multiple platforms instantly.
6. Faster Transactions
Online payments and automated order processing save time.
7. Better Supply Chain Management
Digital systems improve inventory control and logistics.
8. Personalized Marketing
Platforms recommend products based on customer preferences.
Limitations of E-Commerce
Despite its advantages, E-Commerce also faces several challenges:
1. Security Risks
Online fraud, hacking, and data theft are major concerns.
2. Lack of Physical Inspection
Customers cannot touch or test products before purchase.
3. Delivery Issues
Delays, damages, or lost shipments can affect customer satisfaction.
4. Technology Dependence
Requires internet access and digital literacy.
5. Return & Refund Problems
Return processes may be time-consuming.
6. Reduced Personal Touch
No face-to-face interaction, which may affect trust.
7. Legal and Regulatory Issues
Different countries have different e-commerce laws.
4
Key Features of E-Commerce
Electronic Commerce (E-Commerce) refers to buying and selling goods and services over
electronic networks, mainly the Internet. It has several unique characteristics that
distinguish it from traditional commerce.
5
Impact of E-Commerce on Business Organizations
E-Commerce has transformed traditional business models and operational strategies.
Global Market Access
Businesses can reach international customers without opening physical stores, expanding
revenue opportunities.
Reduced Operational Costs
Lower expenses on rent, manpower, and physical infrastructure increase profit margins.
Improved Supply Chain Management
Real-time inventory tracking and automated logistics improve efficiency and reduce wastage.
Data-Driven Decision Making
Companies analyze customer data to forecast demand, personalize marketing, and optimize
pricing.
Faster Business Processes
Ordering, billing, and payments are automated, reducing processing time.
Increased Competition
Small businesses can compete with large firms, leading to innovation and better services.
New Business Models
Models like dropshipping, subscription services, and digital marketplaces have emerged.
6
Economic Impact
Growth of Digital Economy
Boosts online payments, fintech, logistics, and IT services.
Employment Generation
Creates jobs in delivery, warehousing, customer support, digital marketing, and tech
development.
Encouragement to Start-ups
Low entry barriers promote entrepreneurship.
Increased GDP Contribution
Digital trade adds significantly to national income.
Financial Inclusion
Digital payments bring more people into formal banking systems.
Social Impact
Improved Standard of Living
Easy access to goods and services improves quality of life.
Urban–Rural Connectivity
Rural consumers gain access to urban markets.
Women and Youth Empowerment
Home-based online businesses create opportunities for marginalized groups.
Digital Literacy
Promotes use of technology and Internet awareness.
Challenges to Society
Despite benefits, E-Commerce also creates concerns:
• Cybercrime and data privacy issues
• Job losses in traditional retail
• Environmental impact due to packaging and deliveries
• Digital divide between connected and non-connected populations
7
Meaning of Direct Marketing and Selling in E-Commerce
Direct marketing and selling through e-commerce refers to the practice where businesses
sell products or services directly to customers online, using websites, mobile apps, email,
and social media—without relying on traditional retail channels.
Examples include Amazon, Flipkart, company websites, and Instagram shops.
2. Personalized Marketing
E-commerce platforms use customer data to provide:
• Personalized recommendations
• Targeted advertisements
• Customized offers
This increases customer engagement and sales.
Example: Netflix or Amazon recommendations.
3. Email Marketing
Businesses send promotional emails directly to customers, such as:
• Discount offers
• New product launches
• Abandoned cart reminders
It is low-cost and measurable.
8
Businesses sell products directly through:
• Their own websites
• Online marketplaces
Customers can place orders instantly.
Examples: Flipkart, Myntra, Nykaa.
6. Digital Advertising
E-commerce uses:
• Google Ads
• Social media ads
• Banner ads
to reach targeted audiences.
5. Resistance to Change
10
Traditional businesses and customers may prefer offline transactions due to habit or fear of
technology, leading to slow acceptance.
11
Meaning of Value Chain
The concept of the value chain was introduced by Michael Porter.
A value chain refers to the series of activities performed by an organization to design,
produce, market, deliver, and support its products or services, with each activity adding
value to the final offering.
Traditional Value Chain Activities
Porter divided activities into:
A. Primary Activities
1. Inbound Logistics – Receiving and storing raw materials
2. Operations – Transforming inputs into finished goods
3. Outbound Logistics – Distribution to customers
4. Marketing & Sales – Promoting and selling products
5. Service – After-sales support
B. Support Activities
1. Firm Infrastructure
2. Human Resource Management
3. Technology Development
4. Procurement
Each activity contributes to customer value and organizational profit.
12
Role of Value Chains in E-Commerce
1. Cost Reduction
Automation reduces operational and transaction costs.
2. Faster Processes
Online ordering, digital payments, and automated inventory speed up business cycles.
3. Customer Value Enhancement
Personalized recommendations, faster delivery, and 24/7 availability improve satisfaction.
4. Disintermediation
Removal of middlemen allows manufacturers to sell directly to consumers.
5. New Revenue Models
Subscription services, digital products, and online advertising become possible.
13
Supply Chain in E-Commerce
14
• Automated inventory
• Third-party logistics (3PL)
Key components:
1. E-procurement
2. Online inventory systems
3. Order management
4. Digital warehousing
5. Last-mile delivery
7. Features of E-SCM
1. Real-time data sharing
2. Cloud-based systems
3. Automated workflows
4. Vendor portals
5. Customer order visibility
6. AI-based demand forecasting
8. Components of E-SCM
A. E-Procurement
Online purchasing of raw materials.
B. E-Inventory Management
Automatic stock updates.
C. E-Logistics
Tracking shipments digitally.
D. E-Order Processing
Instant confirmation and billing.
E. Customer Relationship Management (CRM)
Customer feedback and service integration.
9. Benefits of E-SCM
1. Reduced inventory costs
2. Faster order fulfillment
3. Improved coordination
4. Increased transparency
5. Better forecasting
15
6. Enhanced customer satisfaction
16
Meaning of Inter-Organizational Value Chain (10 minutes)
Definition:
An Inter-Organizational Value Chain refers to a network of two or more independent
organizations that work together electronically to perform business activities such as
procurement, production, logistics, marketing, and customer service in order to deliver value
to the final customer.
In simple words:
It is a digitally connected chain of different companies that jointly create products or
services.
Example:
Amazon works with:
• Manufacturers
• Warehouses
• Delivery partners
• Payment gateways
All these organizations are digitally linked, forming an inter-organizational value chain.
1. Suppliers
Provide raw materials or products.
Examples:
• Electronics manufacturers
• Packaging suppliers
They connect using:
• EDI (Electronic Data Interchange)
• Supplier portals
2. Producers / Manufacturers
17
Convert raw materials into finished goods.
They use:
• ERP systems
• Inventory management software
• Production planning tools
5. Customers
End users who place orders and provide feedback.
Supplier → Manufacturer → Distributor → Online Retailer → Customer
All connected electronically.
Supporting Technologies:
• Internet & cloud computing
• EDI
• APIs
• ERP systems
• SCM software
• CRM systems
18
Role of E-Commerce in Inter-Organizational Value Chains
E-commerce acts as the backbone of IOVC by enabling:
• Real-time communication
• Online ordering
• Digital payments
• Electronic contracts
• Automated inventory updates
Without e-commerce technologies, such coordination would be slow and inefficient.
5. Increased Transparency
Each organization can monitor:
• Inventory levels
• Shipment status
• Sales data
This builds trust among partners.
19
6. Greater Competitive Advantage
Companies become:
• More flexible
• More responsive
• More innovative
They can adapt quickly to market changes.
7. Scalability
Businesses can easily add new suppliers or partners through digital platforms.
8. Global Reach
Companies can collaborate internationally without physical presence.
Real-World Examples
Amazon Ecosystem
Links sellers, warehouses, couriers, banks, and customers.
Walmart Supply Chain
Uses RFID and cloud systems for supplier integration.
Flipkart
Connects Indian vendors, logistics partners, and payment services.
Challenges
• Data security issues
• Dependency on partners
• System compatibility
• Trust among organizations
20
• Sellers upload products online
• Inventory updated automatically
• Orders processed instantly
• Couriers receive shipping instructions digitally
• Customers track deliveries in real time
21
• Cloud systems
• Supplier portals
Suppliers can directly see Walmart’s inventory levels and plan production.
22
Meaning of Strategic Business Unit
Simple Explanation:
An SBU is a “mini company” within a large organization.
Each SBU behaves almost like a separate business while remaining under the same
corporate umbrella.
1. Independent Strategy
Each SBU develops its own business strategy based on its market conditions.
2. Separate Objectives
Every SBU has specific goals such as revenue growth, market share, or innovation.
3. Distinct Competitors
An SBU competes with different rivals compared to other units of the same company.
4. Dedicated Resources
SBUs often have their own:
• Budget
• Workforce
• Marketing plans
• Operations
5. Performance Measurement
Each SBU is evaluated individually for profitability and growth.
23
Typical Organizational Structure:
Corporate Headquarters
↓
SBU A
SBU B
SBU C
Each SBU contains:
• Marketing
• Operations
• Finance
• HR
This decentralized structure allows faster decision-making.
Example:
In Tata Group, different SBUs include:
• IT services
• Automobiles
• Steel
• Consumer products
Each operates independently while reporting to the central corporate office.
24
Role of SBUs in Strategic Planning
SBUs play a central role in corporate strategy.
Corporate headquarters:
• Reviews performance of each SBU
• Decides expansion or closure
• Approves budgets
• Sets long-term direction
This approach was strongly influenced by strategic thinking frameworks developed by
experts like Michael Porter, who emphasized competitive advantage and focused strategies.
25
Yet all contribute to overall corporate success.
26
An Industry Value Chain refers to the complete sequence of activities performed by
different organizations in an industry — starting from raw material suppliers and ending with
the final customer — where each participant adds value to the product or service.
Simple Explanation:
Industry Value Chain = Value creation by many companies together, not just one company.
27
1. Suppliers
Provide raw materials or components.
Example: chip makers, packaging suppliers.
2. Manufacturers
Convert inputs into finished goods.
They focus on:
• Production efficiency
• Quality control
4. Retailers / Platforms
Sell products to customers.
In e-commerce, these are online marketplaces.
5. Customers
End users who consume the product and provide feedback.
28
↓
Customers
Additional partners:
• Payment gateways
• Cloud services
• Third-party logistics
Here, Amazon does not manufacture most products. It coordinates the entire industry
network digitally.
29
Helps firms understand which stage generates maximum profit.
2. Improves Collaboration
Encourages partnerships between suppliers, producers, and distributors.
3. Enhances Customer Satisfaction
Better coordination leads to:
• Faster delivery
• Lower prices
• Better service
4. Builds Competitive Advantage
Companies compete as networks, not individually.
5. Supports Digital Transformation
Cloud systems, ERP, APIs, and e-commerce platforms integrate the chain.
6. Enables Global Reach
Organizations can participate internationally without physical presence.
30
Security Overview in E-Commerce
Meaning of Security
Security in e-commerce refers to the protection of:
• Information systems
• Networks
• Applications
• Digital transactions
• User identities
from unauthorized access, modification, destruction, or disclosure.
The primary objective is to maintain the CIA Triad:
Confidentiality
Ensures that sensitive information is accessible only to authorized users.
Example: Encrypting credit card numbers during online payments.
Integrity
Ensures data is accurate and not altered during storage or transmission.
Availability
Ensures systems and services are available whenever required by legitimate users.
Failure of any one of these principles can disrupt business operations and destroy customer
trust.
1. Malware Attacks
Malware includes viruses, worms, spyware, trojans, and ransomware.
Effects:
• Steals passwords
• Corrupts databases
• Locks systems for ransom
• Tracks user activities
Ransomware is especially dangerous because it encrypts company data and demands
payment to restore access.
2. Phishing Attacks
Attackers send fake emails or SMS pretending to be banks or shopping sites.
Victims unknowingly share:
• Login credentials
31
• OTPs
• Card numbers
This leads to financial fraud and identity theft.
4. Identity Theft
Personal information is stolen and used to make fake purchases or open fraudulent
accounts.
6. Man-in-the-Middle Attack
An attacker secretly intercepts communication between buyer and seller, capturing
confidential data during transmission.
7. SQL Injection
Malicious SQL code is inserted into website forms to access backend databases.
Results:
• Leakage of customer records
• Modification of product prices
• Deletion of tables
8. Insider Threats
Employees misuse system access either intentionally or accidentally.
Examples:
• Sharing passwords
• Downloading sensitive data
• Misconfiguring servers
32
Stolen card details or fake wallets are used for unauthorized purchases on payment
platforms like PayPal.
1 Physical Security
Protects physical assets such as servers, computers, and networking devices.
Includes:
• CCTV surveillance
• Biometric access control
• Fire safety systems
• Locked data centers
Purpose: Prevent theft, vandalism, and environmental damage.
2 Network Security
Protects data flowing across networks.
Tools:
• Firewalls
• Intrusion Detection Systems (IDS)
• VPNs
• Secure routers
Purpose: Block unauthorized network access and cyber intrusions.
3 Application Security
Protects software applications from vulnerabilities.
Methods:
• Secure coding
• Regular updates and patches
• Web Application Firewalls
• Penetration testing
Purpose: Prevent attacks such as SQL injection and cross-site scripting.
4 Data Security
Protects stored and transmitted information.
Techniques:
• Encryption
• Backup systems
33
• Access permissions
• Data masking
Purpose: Maintain confidentiality and integrity.
6 Operational Security
Defines organizational policies and procedures.
Includes:
• Employee awareness training
• Password policies
• Incident response plans
• Regular security audits
Purpose: Reduce human error and improve preparedness.
34
In today’s digital age, ideas, software, designs, music, books, and inventions are valuable
assets. With rapid growth of information technology and e-commerce, protecting creative
and intellectual work has become extremely important. This protection is provided through
Intellectual Property Rights (IPR).
Intellectual Property Rights give legal recognition to creators and innovators, ensuring they
receive credit and financial benefits for their work while preventing unauthorized copying or
misuse.
Internationally, intellectual property protection is promoted by organizations such as World
Intellectual Property Organization, which helps countries develop laws and standards for
safeguarding creative works.
1 Copyright
Copyright protects original creative works such as:
• Books and articles
• Computer software
• Music and films
• Paintings and photographs
• Websites and digital content
35
Copyright gives the creator exclusive rights to reproduce, distribute, display, and adapt their
work.
For BCA students, copyright is especially important in:
• Software development
• Website design
• Multimedia projects
• Digital documentation
Unauthorized copying of software or online content is considered copyright infringement.
2 Patents
A patent protects new inventions or technical solutions.
It grants the inventor exclusive rights to manufacture, sell, or use the invention for a specific
period.
Examples include:
• New algorithms
• Hardware designs
• Innovative technical processes
3 Trademarks
A trademark protects brand identity such as:
• Logos
• Symbols
• Business names
• Taglines
Trademarks help customers identify genuine products and services.
4 Industrial Designs
Industrial design protection applies to the visual appearance of products, such as shape,
pattern, or color.
5 Trade Secrets
Trade secrets include confidential business information like formulas, strategies, or customer
databases. Protection exists as long as secrecy is maintained.
Copyright
Definition
Copyright is a legal right that protects original literary, artistic, musical, and software works
from unauthorized reproduction.
36
2. Automatically applies once work is created
3. Gives exclusive rights to the creator
4. Has limited duration
5. Can be transferred or licensed
Copyright in Software
For BCA students, software copyright is critical:
• Source code is treated as literary work
• Unauthorized copying of programs is illegal
• Selling pirated software violates copyright law
• Even partial code reuse without permission may be infringement
Copyright Infringement
Copyright infringement occurs when protected material is used without permission.
Common examples:
• Pirated software
• Downloading movies illegally
• Copying project code from the internet
• Using images without attribution
Consequences include:
• Legal penalties
• Financial compensation
• Damage to professional reputation
37
• Customer databases
Strong IPR enforcement builds trust and encourages digital business growth.
38
In today’s digital environment, organizations depend heavily on computer systems,
networks, and online platforms. Sensitive data such as customer records, financial
information, and intellectual property must be protected from cyber threats.
Technology alone cannot ensure protection. A well-defined Security Policy combined with
an Integrated Security approach is essential to safeguard information assets and maintain
business continuity.
Security Policy
Meaning of Security Policy
A Security Policy is a formal written document that defines:
• Rules for using IT resources
• Responsibilities of users and administrators
• Security standards and procedures
• Actions to be taken during security incidents
It acts as a blueprint for organizational security.
39
• Data sharing guidelines
7 Compliance Policy
Ensures the organization follows legal and international standards such as ISO frameworks
developed by International Organization for Standardization (for example, ISO 27001 for
information security management).
40
• Build customer trust
• Meet legal requirements
• Handle cyber incidents effectively
For BCA students, understanding security policy is crucial because future roles may involve
system administration, software development, or IT management.
41
Integrated Security
1 Physical Layer
• CCTV
• Access cards
• Locked server rooms
Prevents physical theft or damage.
2 Network Layer
• Firewalls
• Intrusion Detection Systems
• Secure routers
Protects communication channels.
3 Application Layer
• Secure coding
• Patch management
• Web application firewalls
Protects software from vulnerabilities.
4 Data Layer
• Encryption
42
• Backups
• Access permissions
Protects stored and transmitted information.
5 Identity Management
• User authentication
• Role-based access
• Multi-factor login
Ensures only authorized users enter the system.
6 Monitoring and Auditing
• Log analysis
• Security alerts
• Regular audits
Helps detect threats early.
43
E-commerce systems operate through internet-based platforms involving customers,
businesses, payment gateways, servers, and communication networks. Because transactions
happen digitally, they face multiple security threats.
44
• Encryption
• Licensing agreements
• Watermarking digital content
Effects
• Customer distrust
• Financial loss
• Business shutdown risk
Prevention
• Secure payment gateways
• Multi-factor authentication
• HTTPS encryption
• Fraud detection systems
3. Client Threats
Meaning
Threats originating from the customer’s device (mobile, laptop, tablet).
45
Viruses or spyware installed on user devices.
2. Trojan Horse
Malicious programs disguised as genuine applications.
3. Phishing Attacks
Fake login pages stealing credentials.
4. Keyloggers
Software recording keyboard inputs including passwords.
Example Scenario
A customer logs into an online banking portal while malware captures login details.
Consequences
• Account takeover
• Unauthorized purchases
• Data theft
Protection Measures
• Antivirus software
• Secure browsers
• Avoid suspicious downloads
• Regular updates
Real-Life Example
Using public Wi-Fi without encryption exposes login credentials.
Security Controls
• SSL/TLS encryption
46
• VPN usage
• HTTPS protocols
• Secure cookies
• Network firewalls
5. Server Threats
Meaning
Threats targeting the web server where e-commerce applications and databases are stored.
Impact
• Website downtime
• Loss of confidential data
• Legal penalties
• Revenue loss
Prevention Techniques
• Firewall protection
• Intrusion Detection Systems (IDS)
• Regular security patches
• Access control management
• Backup and disaster recovery plans
47
Future of E-Commerce
Introduction
E-Commerce refers to buying and selling goods and services through electronic networks,
mainly the internet. With rapid technological advancements, digital payments, and changing
consumer behavior, e-commerce is becoming the dominant form of global trade.
The future of e-commerce is driven by:
• Technology innovation
• Digital transformation
• Artificial Intelligence
• Mobile commerce
• Global connectivity
48
• Voice-assisted shopping
3. Social Commerce
Social media platforms are becoming shopping platforms.
Examples
• Shopping via Instagram and Facebook
• Influencer marketing
• Live shopping events
Customers discover and buy products without leaving social apps.
Advantages
• Direct customer engagement
• Faster purchase decisions
• Personalized marketing
5. Voice Commerce
Voice assistants enable hands-free shopping.
Examples
• Voice search
• Smart speaker purchases
• AI assistants placing orders automatically
Growing use of smart devices will increase voice-based transactions.
49
Developments
• UPI payments
• Digital wallets
• Biometric authentication
• Blockchain-based payments
India’s digital payment ecosystem is growing rapidly due to fintech innovations.
50
12. Blockchain Technology
Blockchain increases transparency and trust.
Uses
• Secure payments
• Supply chain tracking
• Fraud prevention
• Smart contracts
Opportunities
• Expansion into rural markets
• Growth of digital entrepreneurship
• New job opportunities
• AI-driven business models
• Global digital economy
51
Implementing Security for E-Commerce
E-commerce involves online transactions between businesses and customers. Because
financial data, personal information, and business data are exchanged over the internet,
strong security mechanisms are essential. Implementing security in e-commerce ensures
that online transactions remain safe, private, and reliable.
1. Confidentiality
Confidentiality means that sensitive information should only be accessible to authorized
users.
Examples of confidential information
• Credit card numbers
• Passwords
• Customer personal details
• Business transaction records
Methods to maintain confidentiality
• Data encryption
• Secure Socket Layer (SSL)
• HTTPS protocol
Example: Websites like Amazon protect user data using encrypted connections.
2. Integrity
Integrity ensures that data is not altered or modified during transmission or storage.
If data is modified by attackers, the transaction may become invalid or harmful.
Example
A hacker changing the price of a product or modifying payment details.
Techniques used
• Hash functions
• Digital signatures
• Secure databases
3. Authentication
Authentication verifies the identity of users involved in the transaction.
It confirms that the person accessing the system is genuine.
Common authentication methods
• Username and password
• Two-factor authentication (2FA)
• Biometric authentication
52
Example: Online marketplaces like Flipkart use OTP verification for login and payment
authentication.
4. Authorization
Authorization determines what actions a user is allowed to perform after authentication.
Example:
• Customers can place orders.
• Administrators can manage products and prices.
Authorization ensures controlled access to system resources.
5. Non-Repudiation
Non-repudiation means that a user cannot deny performing a transaction.
For example:
If a customer places an order, they cannot later claim they did not make the purchase.
Tools used
• Digital signatures
• Transaction logs
• Secure payment confirmations
6. Availability
Availability ensures that e-commerce services are accessible whenever customers need
them.
If a website crashes or is attacked, customers cannot complete transactions.
Measures to ensure availability
• Backup systems
• Cloud hosting
• Protection against DDoS attacks
53
Protecting E-Commerce Assets
E-commerce businesses operate through digital platforms where valuable resources such as
data, infrastructure, and business information are stored. These resources are called e-
commerce assets. Protecting these assets is important to ensure secure transactions,
business continuity, and customer trust.
2. Physical Assets
Meaning
Physical assets refer to tangible resources that support e-commerce operations.
Even though e-commerce is mainly digital, physical infrastructure is essential for running the
system.
54
Protection Measures
• CCTV surveillance
• Physical access control systems
• Backup power supply (UPS, generators)
• Disaster recovery plans
• Secure data center facilities
3. Digital Assets
Meaning
Digital assets refer to intangible electronic resources used in e-commerce operations.
These assets are the most valuable because they store customer information, financial
records, and business data.
Protection Measures
• Encryption techniques
• Secure authentication systems
• Firewalls and intrusion detection systems
• Regular security updates
• Data backup and recovery systems
55
4. Risk Management in E-Commerce
Meaning
Risk management is the process of identifying, analyzing, and controlling risks that may
affect e-commerce assets and operations.
The goal is to reduce potential losses and ensure secure business operations.
1. Risk Identification
The first step is to identify possible threats and vulnerabilities.
Examples of risks:
• Cyber attacks
• System failures
• Data theft
• Fraudulent transactions
2. Risk Assessment
After identifying risks, businesses evaluate:
• Likelihood of the risk occurring
• Possible impact on the business
This helps in prioritizing critical risks.
4. Risk Monitoring
Risks must be continuously monitored and updated as technology and threats evolve.
Regular security audits help identify new vulnerabilities.
56
Intellectual Property (IP) refers to creations of the mind such as inventions, designs, brand
names, software, digital content, and creative works. In e-commerce, businesses rely heavily
on digital assets like websites, software, product images, databases, and brand identity.
Because these assets exist online, they are vulnerable to copying, piracy, and unauthorized
use. Therefore, protecting intellectual property is essential to maintain competitive
advantage, business reputation, and financial security.
Major methods used to protect intellectual property include:
• Encryption
• Digital Watermarking
• Legal Protection
1. Encryption
Meaning
Encryption is a security technique that converts readable data (plaintext) into an
unreadable format (ciphertext). Only authorized users with a decryption key can convert it
back into its original form.
Encryption helps protect intellectual property such as digital documents, software code,
and confidential business data.
Types of Encryption
1. Symmetric Encryption
• Uses the same key for encryption and decryption.
• Faster but requires secure key sharing.
2. Asymmetric Encryption
• Uses two keys: public key and private key.
• Public key encrypts the data.
• Private key decrypts the data.
Applications in E-Commerce
• Protecting website source code
• Securing product databases
• Protecting confidential business documents
• Secure transmission of digital content
Advantages
• Prevents unauthorized access
57
• Protects confidential information
• Ensures secure communication
2. Digital Watermarking
Meaning
Digital watermarking is a technique used to embed hidden information into digital content
such as images, videos, audio files, or documents.
The watermark identifies the original owner of the content, helping prevent unauthorized
copying or distribution.
Applications in E-Commerce
• Protecting product images on online marketplaces
• Securing digital artwork and photographs
• Protecting e-books and online media content
• Preventing content piracy
Example: Online marketplaces such as Amazon often protect digital content like e-books
through watermarking.
Advantages
• Helps identify the original owner
• Discourages piracy
• Maintains authenticity of digital content
3. Legal Protection
Meaning
Legal protection involves using laws and regulations to safeguard intellectual property
rights. Governments provide legal frameworks that protect creators from unauthorized use
of their work.
58
• Digital content
• Books and articles
• Website content
• Images and videos
The creator gets exclusive rights to reproduce, distribute, and modify the work.
2. Trademark
A trademark protects brand identity, including:
• Brand names
• Logos
• Symbols
• Taglines
Example: Logos and brand names used by companies like Flipkart are protected under
trademark laws.
3. Patent
Patents protect new inventions or innovative technologies. The inventor receives exclusive
rights to use or sell the invention for a certain period.
4. Trade Secrets
Trade secrets protect confidential business information such as:
• Algorithms
• Business strategies
• Customer databases
• Marketing plans
59
Protecting Client Computers in E-Commerce
Introduction
In e-commerce systems, the client computer refers to the device used by customers to
access online services. These devices include personal computers, laptops, tablets, and
smartphones used for browsing websites, making online purchases, and performing digital
transactions.
Because client computers interact directly with e-commerce websites, they are vulnerable to
cyber attacks, malware, data theft, and fraud. Therefore, protecting client computers is an
important part of e-commerce security.
2. Phishing Attacks
Phishing occurs when attackers create fake emails or websites that look like legitimate ones
in order to steal sensitive information such as passwords and credit card details.
Example: A fake login page resembling an e-commerce website like Amazon.
3. Keyloggers
Keyloggers are programs that record every keystroke typed by the user, including
usernames, passwords, and banking information.
4. Identity Theft
Attackers steal personal information such as:
• Name
• Address
• Credit card details
They then use this information to perform fraudulent transactions.
5. Browser Attacks
Web browsers may be exploited through:
60
• Malicious scripts
• Insecure plugins
• Fake extensions
These vulnerabilities allow hackers to access sensitive data.
61
• Clicking suspicious links
• Downloading software from untrusted websites
Such actions often lead to malware infections.
6. Using Firewalls
A firewall monitors incoming and outgoing network traffic and blocks unauthorized access.
Firewalls help prevent hackers from accessing client computers remotely.
8. Data Backup
Important files should be backed up regularly.
Backup methods include:
• External hard drives
• Cloud storage services
This helps recover data in case of system failure or cyber attack.
62
Protecting E-Commerce Communication Channels
Introduction
In an e-commerce system, communication channels are the networks and pathways
through which data is transmitted between the customer (client) and the server. These
channels include the internet, wireless networks, and communication protocols used for
online transactions.
Since sensitive information such as credit card numbers, passwords, and personal details
travels through these channels, they must be protected from unauthorized access and cyber
attacks. Protecting e-commerce channels ensures secure, reliable, and trustworthy online
transactions.
3. Data Modification
Attackers may alter the transmitted information, such as:
• Order details
• Payment amounts
• Shipping addresses
This leads to incorrect or fraudulent transactions.
4. Session Hijacking
Session hijacking occurs when attackers take control of a user's active login session,
allowing them to perform unauthorized actions.
1. Encryption
Encryption converts readable information into encoded data that cannot be understood by
unauthorized users.
63
During transmission, sensitive data is encrypted so that even if it is intercepted, it remains
unreadable.
Example
Secure websites use encryption protocols to protect online transactions.
2. SSL/TLS Protocols
Secure Socket Layer (SSL) and Transport Layer Security (TLS) are protocols that provide
secure communication between web browsers and servers.
These protocols:
• Encrypt transmitted data
• Authenticate websites
• Ensure secure connections
Websites using these protocols display HTTPS in the address bar.
Online marketplaces like Amazon use HTTPS connections to secure customer transactions.
3. Digital Certificates
Digital certificates verify the identity of a website or organization.
They are issued by trusted Certificate Authorities (CAs) and ensure that users are
communicating with legitimate websites.
Digital certificates prevent users from accessing fake or fraudulent websites.
64
• Network intrusions
65
Protecting the Commerce Server
Introduction
In an e-commerce system, the commerce server is the central computer that hosts the
online store and manages transactions between customers and the business. It stores
important data such as product information, customer records, payment details, and
transaction histories.
Because the commerce server handles critical business operations, it becomes a major
target for cyber attacks. Therefore, protecting the commerce server is essential to ensure
secure online transactions, data protection, and uninterrupted services.
Many global e-commerce platforms such as Amazon use highly secure server infrastructures
to support millions of transactions.
1. Unauthorized Access
Hackers may attempt to gain access to the server to steal or modify data.
Attackers flood the server with excessive requests, making it unavailable to legitimate users.
3. Malware Attacks
Malicious software can infect the server and damage files or steal sensitive information.
66
Attackers insert malicious SQL commands into web forms to gain unauthorized access to
databases.
5. Data Breaches
Sensitive information such as customer data and payment details may be stolen.
1. Firewall Protection
A firewall acts as a security barrier between the server and the internet.
Functions:
Sensitive data transmitted between clients and the server must be encrypted using SSL/TLS
protocols.
• Login credentials
• Payment details
• Personal data
67
5. Regular Software Updates
Updates include:
• Security patches
• Bug fixes
Access control ensures that only authorized users and administrators can access the server.
Examples:
• Strong passwords
• Multi-factor authentication
Regular backups protect data from loss caused by cyber attacks, system failures, or natural
disasters.
• User access
• Transactions
• System changes
68
Ensuring (Insuring) Transaction Integrity in E-Commerce
Introduction
Transaction integrity in e-commerce refers to maintaining the accuracy, consistency, and
reliability of data during online transactions. It ensures that the information exchanged
between the customer and the business remains complete, correct, and unchanged during
transmission and processing.
If transaction integrity is compromised, attackers may modify payment details, product
prices, or order information. Therefore, maintaining transaction integrity is essential for
secure online business operations.
1. Encryption
Encryption protects transaction data during transmission.
• Converts readable information into coded form.
• Only authorized users can decode the data.
Encryption ensures that attackers cannot read or modify transaction information.
69
2. Digital Signatures
A digital signature verifies the authenticity and integrity of a transaction.
Functions
• Confirms the identity of the sender.
• Ensures that data has not been altered.
• Provides non-repudiation.
If data is modified after signing, the signature becomes invalid.
3. Hash Functions
A hash function converts data into a unique fixed-length code called a hash value.
If even a small change occurs in the data, the hash value changes completely.
This helps detect data tampering.
5. Authentication Systems
Authentication ensures that only legitimate users can initiate transactions.
Methods include:
• Password authentication
• Two-factor authentication (2FA)
• Biometric verification
7. Database Security
Databases storing transaction data must be protected using:
• Access control mechanisms
• Encryption
• Regular backups
This prevents unauthorized modification of transaction records.
70
Importance of Transaction Integrity
Ensuring transaction integrity helps:
• Maintain accurate financial records
• Prevent fraud and cyber attacks
• Protect customer trust
• Ensure smooth business operations
• Avoid legal and financial losses
Conclusion
Transaction integrity is a fundamental requirement for secure e-commerce systems. By
using technologies such as encryption, digital signatures, hash functions, and secure
communication protocols, businesses can ensure that online transactions remain accurate,
reliable, and protected from unauthorized modifications.
Maintaining transaction integrity ultimately builds customer confidence and long-term
success in digital commerce.
71
Electronic Payment System (EPS)
1. Introduction
An Electronic Payment System (EPS) is a mechanism that enables cashless transactions
through electronic means such as the internet, mobile devices, and computer networks.
In modern e-commerce, EPS acts as the backbone of online business, allowing customers
and businesses to exchange money quickly, securely, and efficiently without physical cash.
The rapid growth of digital platforms, smartphones, and fintech innovations has made EPS
an essential component of the digital economy.
2. Definition
An Electronic Payment System can be defined as:
“A system that facilitates the transfer of money electronically between a buyer and a seller
using digital technologies and communication networks.”
72
3. Enters payment details (card/UPI/wallet)
4. Payment gateway encrypts data
5. Request sent to issuing bank
6. Bank verifies user credentials
7. Transaction approved or declined
8. Confirmation sent to merchant and customer
9. Funds transferred to merchant account
73
• Fraud detection and prevention
• Infrastructure limitations in rural areas
74
Electronic Wallets (E-Wallets)
1. Introduction
An Electronic Wallet (E-Wallet), also known as a Digital Wallet, is a software-based system
that allows users to store money and payment information electronically and perform
online or offline transactions.
E-wallets are widely used in e-commerce to make fast, secure, and cashless payments using
smartphones, computers, or other digital devices.
3. Features of E-Wallets
• Cashless Transactions – No need for physical cash
• Convenience – Easy and quick payments
• Security – Protected by passwords, PIN, OTP, biometrics
• Portability – Accessible via mobile devices
• Transaction History – Records of all payments
• Multi-functionality – Bill payments, recharge, ticket booking
1. Closed Wallet
Meaning
A wallet issued by a specific company and used only within that company’s platform.
Example
Wallet balance usable only on a particular website.
2. Semi-Closed Wallet
Meaning
Can be used at multiple merchants but does not allow cash withdrawal.
Examples
Popular semi-closed wallets include Paytm and PhonePe.
3. Open Wallet
Meaning
Allows users to:
• Make payments
• Transfer funds
75
• Withdraw cash
Usually issued by banks.
5. Components of an E-Wallet
• User Account – Stores user information
• Payment Information – Card details, bank account, UPI ID
• Digital Balance – Stored money
• Security Features – PIN, OTP, biometric authentication
• Transaction Records – History of payments
76
10. Security Issues in E-Wallets
• Unauthorized access
• Phishing attacks
• Malware threats
• Loss of mobile device
Security Measures
• Strong passwords and PIN
• Two-factor authentication (OTP)
• Biometric verification
• Regular app updates
• Avoiding public Wi-Fi for transactions
77
These are important electronic payment instruments used in e-commerce and digital
transactions.
1. Smart Card
Meaning
A Smart Card is a plastic card embedded with a microchip that stores and processes data
securely. It is more advanced than traditional magnetic stripe cards.
Disadvantages
• Costly compared to normal cards
• Requires compatible devices
• Risk of damage to chip
78
2. Credit Card
Meaning
A Credit Card is a payment card that allows users to borrow money from a bank or financial
institution to make purchases, with repayment at a later date.
Disadvantages
• High interest rates
• Risk of overspending
• Possibility of fraud
• Late payment penalties
3. Charge Card
Meaning
A Charge Card is similar to a credit card but requires the user to pay the full balance at the
end of each billing cycle.
79
Working of Charge Card
1. User makes purchases
2. Bank records transactions
3. Monthly bill is generated
4. User must pay entire amount
Disadvantages
• Full payment mandatory
• High penalties for non-payment
• Not widely accepted everywhere
5. Importance in E-Commerce
These payment instruments:
• Enable secure online transactions
• Provide convenience to users
• Support global payments
• Reduce dependence on cash
• Improve customer experience
80
Basis Credit Card Charge Card
Minimum payment allowed; Full payment is compulsory every
Payment Option
balance can be carried forward month
Interest is charged on unpaid No interest (since full payment is
Interest Charges
balance required)
Usually no preset limit (depends
Spending Limit Predefined credit limit set by bank
on user profile)
Late payment leads to interest + Heavy penalties if full payment is
Penalty
penalties not made
More flexible due to partial Less flexible due to strict full
Usage Flexibility
payment option payment rule
Financial Encourages strict financial
May encourage overspending
Discipline discipline
Annual Fees Moderate or sometimes free Generally higher annual fees
Acceptance Widely accepted globally Less common than credit cards
Examples
Buy now, pay later with installments Buy now, pay fully at month end
(Conceptual)
81
1. Introduction
Business-to-Business (B2B) E-Commerce refers to the electronic exchange of goods,
services, and information between business organizations using digital platforms such as
the internet, intranet, and extranets.
It is the largest segment of e-commerce, as most commercial transactions occur between
businesses rather than between businesses and consumers.
82
2. Buyer-Oriented Model (Buy-Side Model)
Meaning
In this model, a large buyer invites multiple suppliers to bid for products or services.
Key Features
• One buyer, many suppliers
• Competitive bidding (reverse auction)
• Buyer controls the platform
Working
• Buyer posts requirements
• Suppliers submit quotations
• Buyer selects the best offer
Advantages
• Cost reduction through competition
• Better supplier selection
• Transparent pricing
Example
Large companies sourcing raw materials from multiple vendors.
83
• Owned by multiple organizations
• Focus on specific industry
• Shared standards and processes
Working
• Industry players collaborate
• Platform used for procurement and supply chain
• Standardized transactions
Advantages
• Industry-wide efficiency
• Reduced transaction costs
• Better collaboration
6. E-Procurement Model
Meaning
An electronic system used by organizations to purchase goods and services online.
Key Features
• Automated procurement process
• Digital purchase orders and invoices
• Supplier management
Working
• Organization identifies need
• Sends request electronically
• Supplier fulfills order
Advantages
84
• Reduced paperwork
• Faster procurement
• Cost savings
5. Dependence on Technology
• System failure can disrupt operations
85
.Introduction to EDI
Meaning
Electronic Data Interchange (EDI) is the computer-to-computer exchange of business
documents in a standardized electronic format between organizations without human
intervention.
Definition
“EDI is the structured transmission of business data between organizations electronically
using standard formats.”
Example
A retailer sends a purchase order electronically to a supplier, and the supplier automatically
processes it without manual entry.
2. Features of EDI
• Standardized Format (e.g., EDIFACT, ANSI X12)
• Computer-to-Computer Communication
• No Paperwork
• High Speed and Accuracy
• Automation of Business Processes
3. Benefits of EDI
86
• Transactions occur in seconds
• Faster order processing
• Reduced delays
2. Cost Reduction
• Eliminates paper, printing, and postage costs
• Reduces labor costs
• Minimizes administrative expenses
3. Accuracy and Reduced Errors
• No manual data entry
• Fewer human errors
• Improved data quality
4. Improved Business Relationships
• Faster communication
• Reliable transactions
• Better coordination with partners
5. Better Inventory Management
• Real-time updates
• Reduced stock shortages
• Efficient supply chain
6. Increased Productivity
• Automation of repetitive tasks
• Employees can focus on strategic work
7. Enhanced Security
• Secure data transmission
• Controlled access
• Reduced risk of data loss
4. Limitations of EDI
• High initial setup cost
• Requires technical expertise
• Compatibility issues between systems
• Dependence on standards
5. EDI Technology
EDI technology refers to the tools, systems, and processes used to exchange electronic
business documents.
1. EDI Standards
Standard formats ensure uniform communication.
87
Common Standards:
• EDIFACT (International standard)
• ANSI X12 (Used in USA)
2. EDI Software
Software that converts business data into EDI format and vice versa.
Functions:
• Data translation
• Document processing
• Communication handling
3. Communication Network
EDI data is transmitted through:
Types:
• Value Added Network (VAN)
• Internet (Web-based EDI)
• Direct connections
4. EDI Translator
• Converts internal data into standard EDI format
• Converts received EDI data into readable format
5. Business Applications
ERP or accounting systems that:
• Generate documents
• Receive and process EDI data
6. Types of EDI
7. Working of EDI
Step-by-Step Process:
88
1. Business document is created (e.g., invoice)
2. EDI software converts it into standard format
3. Document is transmitted through network
4. Receiver’s system receives document
5. EDI translator converts it into readable format
6. Data is processed automatically
8. EDI in E-Commerce
EDI plays a major role in:
• B2B transactions
• Supply chain management
• Inventory control
• Logistics coordination
Example: Platforms like Alibaba Group use automated systems similar to EDI for large-scale
B2B transactions.
89
1. System detects low stock automatically
2. Computer generates Purchase Order (PO)
3. PO is sent directly to supplier’s system (EDI)
4. Supplier’s system automatically:
o Receives order
o Processes it
o Generates invoice
5. Goods are shipped immediately
90
Meaning of EDI Technology
EDI Technology is the technical infrastructure that supports the creation, transmission,
translation, and processing of electronic business documents in a standardized format.
1. EDI Standards
Meaning
Standard formats used to structure electronic documents.
Common Standards
• EDIFACT (international)
• ANSI X12 (widely used in the USA)
Purpose
• Ensure uniform communication
• Avoid data misinterpretation
3. Communication Technology
EDI requires a network to transmit data.
Types:
a) Value Added Network (VAN)
• Third-party service provider
• Provides secure transmission
• Stores and forwards messages
b) Internet-Based EDI
91
• Uses internet protocols (HTTP, FTP)
• Cost-effective and widely used
5. Security Technologies
EDI uses various security mechanisms:
• Encryption – Protects data
• Authentication – Verifies identity
• Digital Signatures – Ensures integrity
• Access Control – Restricts unauthorized users
92
1. Introduction
EDI Standards are predefined formats and rules used to structure electronic business
documents so that different organizations can communicate and exchange data accurately
and efficiently.
Without standards, each company would use different formats, making data exchange
difficult and error-prone.
1. Data Elements
• Smallest unit of information
• Example: price, quantity, date
2. Data Segments
• Group of related data elements
• Example: customer details segment
3. Messages (Documents)
• Complete business document
• Example: invoice, purchase order
4. Codes and Identifiers
• Standard codes for countries, currencies, products
93
1. EDIFACT (Electronic Data Interchange for Administration, Commerce and Transport)
Developed by: United Nations
Features
• International standard
• Widely used across the world
• Supports multiple industries
Uses
• Trade
• Shipping
• Logistics
2. ANSI X12
Developed by: American National Standards Institute
Features
• Commonly used in the USA
• Industry-specific standards
Uses
• Healthcare
• Retail
• Finance
3. TRADACOMS
Developed in: UK
Features
• Used mainly in retail sector
• Older standard
4. ODETTE
Used in: European automobile industry
Features
• Designed for automotive supply chains
5. RosettaNet
Used in: Electronics and IT industries
Features
• XML-based standard
• Supports modern web technologies
94
1. Introduction
EDI Communication refers to the electronic transmission of standardized business
documents between organizations through communication networks.
It is a crucial part of EDI because it ensures that data is transferred quickly, securely, and
accurately from one business system to another.
95
• Reliable delivery
• Error handling
Disadvantages
• Expensive
96
1. Introduction
EDI Implementation refers to the process of planning, setting up, and integrating an EDI
system within an organization to enable electronic exchange of business documents with
trading partners.
It involves technical, organizational, and strategic steps to ensure smooth and secure data
exchange.
Activities:
Activities:
• Cost-benefit analysis
• Technical feasibility
• Organizational readiness
Options:
• VAN-based EDI
• Web-based EDI
• Cloud-based EDI
Decision Factors:
• Cost
• Security
• Scalability
Common Standards:
• EDIFACT
97
• ANSI X12
Requirements:
• Computers/servers
• EDI software (translator)
• Communication network
Meaning:
Activities:
• Data mapping
• Integration with ERP/SCM systems
Activities:
Step 8: Testing
Types of Testing:
• Internal testing
• Partner testing
Purpose:
Step 9: Training
Activities:
• Train employees
98
• Provide technical knowledge
Activities:
• System monitoring
• Error handling
• Regular updates
99
Introduction
An EDI Agreement is a formal contract between two or more trading partners that defines
the terms, conditions, and rules for exchanging electronic data using EDI systems.
It ensures that both parties clearly understand:
• How data will be exchanged
• What standards will be used
• How security and responsibilities are handled
. Types of EDI Agreements
100
8. Legal Validity
• Recognition of electronic documents as legal proof
• Compliance with laws and regulations
9. Liability and Dispute Resolution
• Responsibility for errors or delays
• Procedures for resolving disputes
10. Audit and Record Keeping
• Maintenance of transaction records
• Audit rights
11. Termination Clause
• Conditions under which agreement can be ended
101
EDI Security refers to the measures, techniques, and policies used to protect electronic
business data exchanged between organizations through EDI systems. It ensures that
sensitive information like invoices, purchase orders, and financial data remains safe,
accurate, and accessible only to authorized users.
102
• Data breaches – Unauthorized access to sensitive data
• Man-in-the-middle attacks – Interception of communication
• Malware & ransomware – Disrupt operations and steal data
103