Notes
Notes
© Printed in India
V RAJARAMAN
Supercomputer Education & Research Centre, Indian Institute of Science,
Bangalore 560 012, India
e-mail: rajaram@[Link]
1. Introduction
A major revolution has taken place during the last five years in the way business is done.
This revolution is primarily due to the convergence of computers and telecommunication
technologies and the emergence of a number of Internet Service Providers (ISPs) who
facilitate the connection of computers to the internet–the world wide network of com-
puters. Internet has spawned a number of innovations in business between commercial
organizations, between individuals and commercial organizations, and between individuals
and individuals. These transactions are commonly known as business-to-business (B2B),
business-to-customer (B2C) and customer-to-customer (C2C) electronic commerce and is
abbreviated as e-commerce. These transactions include orders sent to vendors to supply
items, invoices sent by vendors, payment usually made by debiting an organization’s account
89
90 V Rajaraman
and crediting the vendor’s accounts with banks, and payments made using cre1dit cards.
The important point is that all transactions are carried out electronically using a network of
computers.
One may define e-commerce as “the sharing of business information, maintaining business
relationships and conducting business transactions using computers inter-connected by a
telecommunication system”. The telecommunication system may be a public network (as
used in internet) or a secure private network. There are a variety of e-commerce applications.
Some of these are as listed below.
• Retail stores such as those selling books, music, toys etc.
• Auction sites using which an individual buyer/seller can buy/sell goods.
• Cooperating businesses connected using their own private telecommunication network
carrying out transactions in a semi-automated way.
• Banks connected to their customers providing services such as deposits, payments, and
providing information on status of an account.
• Railways/airlines/cinema theatres permitting booking of tickets on-line and paying for
them on-line using credit cards or electronic cash.
• Filing tax returns with government agencies on-line and obtaining immediate acknowl-
edgements.
• Electronic publishing to promote marketing, advertising, sales and customer support.
• Web-based educational material which allow students to learn anytime and anywhere.
One of the earliest B2C e-commerce application was a book shop. Selling books using
the internet is an excellent choice for promoting e-commerce as it is difficult and expen-
sive for a physical book shop to stock a large number of books and allow customers to
browse before they buy. The catalogue of an e-bookshop can be of very large size and
store a huge quantity of information on books, such as excerpts, reviews, summaries, other
books by the same author etc., which can be provided to a prospective buyer. A major
problem is prompt delivery of books and ensuring the security of a customer’s credit
card details. This business model can be copied very quickly by others leading to fierce
competition.
A major success story in India of B2C is the reservation of railway tickets. Using a site
maintained by the Indian Railways ([Link]) one can book train tickets from anywhere,
anytime (it is a 24 × 7 service). Payment is by credit card and the ticket is delivered by courier
at a customer’s doorstep. It is estimated that currently the monthly volume of ticket sales is
Rs. 8 Crores and 4000 tickets are booked on-line everyday.
C2C e-commerce is the one used by two individuals who want to sell/buy items. Such
items are usually second-hand things, antiques etc. The seller posts the description of
the item and the expected price on a web site maintained by a facilitating company. A
website called e-Bay pioneered this idea in USA, and usually acts as an intermediary. In
India, a site called [Link] (since acquired by e-Bay) is a popular C2C auction site.
A prospective buyer looks at the postings in [Link] and enters his offer for the item.
When several buyers are interested, the highest bidder (within a specified deadline) wins
the auction. The items are collected by the intermediary, delivered to the customer and
the payment is then sent to the seller. The intermediary gets a commission from both
parties.
B2B is perhaps the most important mode of e-commerce. In the long run, it will be eco-
nomically the most significant application of e-commerce. In B2B e-commerce, cooperating
businesses carry out transactions such as placing an order, receiving an invoice for payment,
Building blocks of e-commerce 91
paying bills etc., electronically. Typical applications of e-commerce by businesses are listed
below.
(1) Publishing on-line catalogues and price lists on their website.
(2) Placing tender requests on their websites.
(3) Tracking supply chains to minimize delays.
(4) Just-in-time supply to minimize inventory. For example, a manufacturer may allow his
suppliers to inspect his inventory data base and production schedule. This will allow
suppliers to adjust their own production schedules to meet prospective demands for items
and supply them just in time.
However, the advantages far outweigh the disadvantages and it is becoming increasingly
evident that e-commerce will proliferate rapidly in many areas such as buying tickets, paying
bills, ordering goods and transacting most business.
The rest of this article is organized as follows. In § 2, we describe a layered architecture
of e-commerce systems (Kalakotta & Whinston 1999). This division of the architecture into
layers allows us to organize our discussion of building blocks of e-commerce in a logical
sequence. There are 6 layers in the suggested architecture. In succeeding sections each of
these layers are described in some detail. In § 3, we very briefly describe what we call the
physical layer, namely, the hardware infrastructure for e-commerce. Section 4 describes the
logical layer, namely, the internet which is the backbone for e-commerce. In § 5, important
applications which use the internet are discussed, of which the important ones are the world
wide web and other applications using the web. In § 6, we describe the messaging layer which
deals with secure communication on the internet infrastructure. In § 7, we elaborate on the so-
called middlemen services, that is, services provided by various entities to facilitate monetary
transactions and services that can be outsourced by organizations wanting to participate in e-
commerce. The topmost layer, namely, applications of e-commerce, has already been detailed
in this section. In § 8, we discuss some emerging applications primarily in mobile commerce.
We also examine the legal framework which has become essential for promoting e-commerce.
The problems are both legal and ethical, particularly while examining intellectual property
rights in the age of internet and e-commerce. India is one of the first countries to have enacted
an information technology act with the intention of promoting e-commerce. Some aspects of
this act and some gray areas of this act are discussed in this section. We state our conclusions
in § 9.
92 V Rajaraman
computers which is turn has resulted in the emergence of mobile commerce, abbreviated to
m-commerce.
We call the next layer the logical layer, as it defines protocols (i.e. a set of mutually agreed
rules) to communicate logically between computers connected by the physical network. Inter-
net is a world-wide network of computers that communicate with one another using a partic-
ular protocol known as TCP/IP (Transmission Control Protocol / Internet Protocol).
The world wide acceptance of this standard has led to the emergence of the internet as the
essential infrastructure for e-commerce. The simplicity of connecting computers from diverse
manufacturers using TCP/IP protocol led to the explosive growth of the internet and its wide
acceptance. Organizations found it attractive to use the same protocol, namely, TCP/IP to
interconnect computers within their organization. A major advantage of doing this, besides
allowing the organization to interconnect computers made by different manufacturers, is the
availability of many services such as e-mail, file transfer, protocol, browsing etc., available on
the internet, that may be adopted inexpensively within an organization. Such a local network
within an organization is called intranet. The internet allows anyone to connect to it. It is
thus vulnerable to misuse by anti-social elements who break into others’ computers and steal
or destroy valuable files. Special precautions are required to prevent unauthorized access.
This is provided by what are known as firewalls which guard the intranets of organizations.
Firewalls do not provide absolute security from intruders. Thus many organizations do not
connect their intranet to the internet.
This however would prevent electronic communication among cooperating organizations.
Therefore many cooperating organizations lease communication lines and create a private
network interconnecting their intranets. The protocol is, of course, TCP/IP. Such a private
network interconnecting cooperating organizations is known as an extranet. A private network
formed by leasing communication lines is expensive compared to using the internet. Thus
a method of ensuring secure communication between cooperating organizations using the
internet has been designed. This is called a virtual private network (VPN) (Ben-Ameur &
Kerivin 2003).
The next higher layer is the network services layer. This provides services on the inter-
net infrastructure. The most important service originally was the e-mail service. Currently,
the most important service is the world wide web service which provides users convenient
access to information stored in computers anywhere in the world. Other services which make
e-commerce possible are: html (hyper text markup language), XML (extensible markup lan-
guage), browsers and search engines.
Among the most important requirements of e-commerce is exchanging messages and doc-
uments between participants in e-commerce. For example, purchase orders, delivery notes
etc., have to be sent electronically. The cheapest means of doing it is using the internet. In C2B
and C2C e-commerce, internet is the only available system. As was pointed out earlier, the
internet being accessible to everyone there is always the danger of messages and documents
being maliciously altered by unscrupulous persons. Thus, there is a need to send messages
which are coded using a secret code. It is also necessary to have an equivalent of signing in
the electronic medium. These requirements namely encrypting messages to ensure security
and digital signature to authenticate communications received electronically are provided by
the messaging layer.
We call the next layer “middleman services”. They are essentially services provided to e-
commerce participants to make their dealings easier. Some important middleman services are
secure payments using credit cards, imitating cash payments for small purchases and authen-
tication of digital signatures. Value-added networks provide secure electronic transactions
94 V Rajaraman
among participants. Hosting services provide among other facilities, web presence for orga-
nizations and electronic catalogues and directories etc., to participants.
All the services provided by the layers described above are essential to support e-commerce
application, namely, C2B, B2B and C2C e-commerce. This is thus the top layer in the layered
architecture.
In the rest of this article, we will describe in greater detail each of these layers and how
they cooperate to provide e-commerce solutions for many day-to-day needs of persons and
organizations.
3. Physical layer
If computers are to communicate with one another, they should be physically connected.
Most businesses have a local area network (LAN) connecting all their computers. The LAN
usually connects machines with an unshielded twisted pair (UTP) of copper wires. Computers
connected to a LAN using UTP can communicate at the rate of 1 gigabit/second, even though
100 megabits/second is more common. The number of computers that can be connected to
a segment of a LAN is limited to around 16. Larger LANs are made by connecting smaller
LAN segments by what are known as bridges. Besides UTP, one may use fibre optic cables to
interconnect computers if higher speed is needed. Mobile computers may also be connected
to a LAN using wireless communication. Those interested in detailed information on physical
networks may refer to Stallings (1998).
When two businesses want to communicate with each other, their LANs are connected
using what is known as a router to the telephone network provided by the Department of
Telecommunications (DOT). This network is known as a Public Switched Telephone Network
(PSTN). PSTNs are not very secure. Thus, if two businesses want to closely collaborate and
want high security they have to use their own private leased communication lines.
4. Logical network
The single most important technology which has enabled the growth of e-commerce is the
internet. The internet connects tens of millions of computers spread all over the world enabling
them to exchange information and share resources (Comer 1995). The major applications of
internet are exchange of electronic mail, exchange of files (text as well as multimedia), storing
information in a form which allows other computers connected to the internet to access it, and
remote logging onto a computer and using it to run programs. For two computers in different
locations to communicate, it is necessary that the following conditions hold.
The unique address required by a computer in order to access the internet is called its
IP address. The IP address is a 4-byte address and is expressed in what is known as the
Building blocks of e-commerce 95
dotted decimal format, e.g. [Link]. The IP address for a business or an individual is
provided by the Internet Service Provider (ISP). IP addresses are an important and scarce
resource particularly because the number of computers connected to the internet is rapidly
growing. The IP address is converted into a string of characters for ease of remembering
and grouped into domains. For example in the address: [Link], the top domain is the
country name abbreviated in, the ISP is ernet, who is the host of iisc. IP addresses are
controlled by an international authority known as Internet Corporation for Assigned Names
and Numbers (ICANN), and a hierarchical organization of addresses allows this authority to
decentralise the assigning of addresses. For example, ernet is given a range of IP addresses
by ICANN and it allocates a subset of addresses to iisc, which in turn allocates addresses to
various departmental servers. The clients connected to the departmental servers are then given
their unique address by the department. Domain names are very important in e-commerce
as they provide immediate brand recognition. Thus, there has been a problem known as
cyber squatting which has led to legal wrangles. Cyber squatting is the registering of a well-
recognized name as one’s own domain name to prevent an organization or company from
using it. Resolution of disputes on domain names is currently done by ICANN. However,
there is a move to refer international disputes to the World Intellectual Property organization
which currently resolves disputes on copyright, trademark etc.
The internet protocol breaks up a message sent from a source to a destination into a number
of packets. A packet consists of two parts, the part containing the information which is
called the payload and a part called the header (see figure 1). The header consists of the
source and destination addresses, the serial number of the packet, error detection bits and
other control bits, and is used to route the packet to the destination address. Messages are
broken into packets as this reduces the cost of transmission and improves the fault-tolerance
of transmission. The cost of transmission is reduced as a number of packets (that may belong
to different messages) can be assembled and sent along any free communication channel.
The packets are stored in routers along the path and forwarded to another router when the
communication link is free. This is called packet switching. It is also fault-tolerant because
if a line is not working, the stored packet can be sent along another line which is working.
Observe that different packets belonging to a message may travel along different paths. They
are finally assembled at the destination using the serial number of each packet. The major
disadvantage of packet switching is that the time taken for a message to reach a destination
cannot be predicted. This is not a disadvantage for applications such as e-mail, file transfer
etc., but is a disadvantage for real-time messages such as telephone conversations and video
transmissions. Currently, work is going on to improve the internet protocol to allow real-time
data transmission also. One of the major advantages of internet, as already mentioned, is its
ability to connect computers from any manufacturer and LANs using different technologies
together into a uniform access system by enforcing that the computers use a software layer
conforming to the internet protocol known as TCP/IP (Transmission Control Protocol/Internet
Protocol).
5. Network layer
The World Wide Web is a global multimedia information service available on the internet. It
consists of linked web pages (or documents). Each web page is prepared using a language
known as HTML (Hyper Text Markup Language). HTML has features to embed links within
web pages pointing to other web pages, multimedia files and data bases. Web pages are stored
on what are known as web servers. A web server can host one or more web pages. Observe
that the world wide web is not internet. Internet provides the infrastructure on which the world
wide web is built.
To locate a web page stored in the world wide web, a scheme known as uniform resource
locator (URL) is used. An example of a URL is given below:
[Link]
In this example http specifies the protocol to be used. In this case it is hypertext transfer
protocol. This is the protocol used for web search. [Link] preceded by :// is the
address (called domain name) of a computer (called a server) which is permanently connected
to the internet. The computer may be located anywhere in the world. The part of the URL,
namely, /connected/[Link] is a path to the required file which stores the information. In
this case the document [Link] is stored in a folder named “connected”.
There are other protocols used in the internet for other services. For example ftp:// is used
for transferring files from one computer to another connected to the internet. ftp stands for
file transfer protocol. For example [Link] transfers the contents of the
specified file to a user’s computer if he/she has access permission from the server.
The information on a web page can be retrieved by a customer (or user) using a web
browser program which runs on his/her desktop computer connected to the internet. There
are many web browsers, the most popular of which are Netscape and Internet Explorer. The
URL is entered in the location field of the browser screen. The browser program connects
to the specified web server, and displays the document on the browser screen. Web browsers
have excellent Graphical User Interface (GUI) which simplifies access to web pages. Most
organizations now maintain a web page on a server in their organization or on a server which
is rented by a service agency. Hosting of the web pages of many organizations has now
become an important business. These businesses keep a large number of powerful servers
on their network with reliable connection to the internet. They create the web pages for
different organizations, based on specifications given by them, and continuously update them
on request from the contracting organizations. Web presence is now essential for any business
as it publicises their activity. Besides organizations, individuals also create and maintain web
pages to “sell themselves”.
In order to create a web page, a language is needed which formats the page with pleasant
background colours, graphics, links to other parts of the same document and links to other web
pages, either in the same server or other servers. This language is called Hypertext Markup
Language (HTML). Hypertext markup language adds tags to text which can be interpreted
by any program. A simple example is given below.
<HTML>
<HEAD>
<TITLE> </TITLE>
</HEAD>
<BODY>
<H1> Analysis and Design of Information Systems </H1>
Building blocks of e-commerce 97
<P> This is the <B> second edition </B> of <I> Rajaraman’s </I> book </P>
</BODY>
</HTML>
Observe the various commands introduced with the text. Some of them are:
Observe that when a web page is designed, selected words are picked and tagged with anchor
commands. When these words are clicked on, the tag activates a link to the specified page,
graphics file, audio or video file. As the use of inter- and intranets increases, most documents
are now created using HTML format. Standard word processor outputs can be converted to
HTML format using tools. There are also specialised tools available to create web pages.
HTML is based on a much larger standard language known as Standard Generalized Markup
Language (SGML). A dialect of SGML called XML (Extended Markup Language) is now
becoming more popular as it allows designing documents tailored to a select audience (Pardi
1999).
The number of web pages in the world wide web runs into tens of millions and is continu-
ously growing. Documents in the web are often poorly structured but do contain very useful
information sometimes along with poor quality unauthenticated information. Finding rele-
vant documents is not easy. There are many tools known as search engines (Rajasekhar 1998;
Brewer 2002) which aid users in their search. These engines (which are actually search pro-
grams) receive a user’s query, systematically explore the web to locate documents, evaluate
their relevance and return a rank-ordered list of documents to the user. Currently the most
popular search engine is [Link].
6. Messaging layer
Electronic commerce generally uses a public switched telephone network (PSTN) and often
occurs between entities who are not known to one another. Ensuring security of communi-
cation between the entities participating in e-commerce is hence an important requirement
(Shim et al 2004) Apart from ensuring the security of messages, an organization should pro-
tect data stored in computers that are connected to the internet from malicious damage. It is
also necessary to be able to authenticate messages received via the internet. In this section, we
98 V Rajaraman
will describe filters which protect an organization’s network from intruders, encryption meth-
ods to ensure secrecy of message contents and stored data and digital signature to authenticate
messages received from customers or business associates.
6.1 Filters
A filter is a computer program or a piece of hardware (with associated software) used to
monitor message packets which enter or leave an organization’s network (figure 2). One may
decide to allow a message packet to enter or leave the network, based either on the information
contained in the header of the packet or the contents of the packet. The header contains the
internet source and destination addresses (IP addresses) and the port number which identifies
the internet service, namely, telnet, ftp, http etc.
A commonly used filter is called a firewall (Cheswick & Belleroin 1994). The simplest
firewall allows access to an organization’s network only to a specified set of IP addresses.
Another screening rule may be to allow outsiders to access only one IP address in the orga-
nization which may be hosting its web page. The other two filters that are commonly used
are for filtering out junk e-mail (called spam) entering a system and for preventing specified
material from entering a system while users are browsing the web. Junk e-mail filters scan the
“From”, “X-Sender” and “Subject” fields in the header of a message. If these are in a list of
unsolicited known junk mailers the messages are deleted. Automatic deletion may sometimes
delete legitimate email and careful monitoring is needed.
data one needs a key which is used to decrypt the message. Messages to be encrypted are also
known as plain text and encrypted messages are known as cryptograms or ciphertext.
There are two methods of encryption. One of them is called symmetric or private key
encryption and the other, public key encryption (Stallings 1999). In symmetric key encryption,
a message sent on a PSTN is encrypted using a key (i.e. it is transformed using a transforma-
tion). The receiver applies the inverse transformation (as he knows the key) and recovers the
message (see figure 3). A common method uses a combination of permutation and substitu-
tion on the plain text to obtain the ciphertext.
This general idea is used in a very popular encryption method called the Data Encryption
Standard (DES) introduced by IBM in 1975 and standardized by the US Government in 1977.
DES was reasonably secure, i.e., trying out all possible keys exhaustively to break the code
took too long till recently. However, with the increasing speed of computers, it has now become
insecure. A system called triple DES which is based on DES is very secure and is currently
used (Stallings 1999). We will first briefly describe DES. DES applies transformations on
blocks of 64-bits corresponding to binary encoding (may be ASCII) of a message text. The
plain text is exclusive ORed with the key to obtain the ciphertext (A ⊕ B = A.B + A.. B
where ⊕ is an exclusive OR operator). If the key is exclusive ORed with the ciphertext we
get back the original plain text as shown below.
This general idea is used in DES. DES encrypts 64-bit blocks. First, the 64-bits are permuted
with a secret key. The resulting block is divided into two 32-bit blocks (Li , Ri ) which are the
left and right half of each block. The following complex procedure is applied 16 times.
Li+1 = Ri ,
Ri+1 = Li ⊕ f (Ri , Ki )
where Ki is the secret key used in the i th round and f a complex function which uses both
permutation and substitution operations and depends on the key. The resulting block is again
permuted using the secret key to obtain the final encrypted block. DES was designed to be
implemented in hardware. Integrated circuit chips implementing DES have been marketed. As
we stated earlier, with the increasing speed of computers DES is now not secure. Thus triple
100 V Rajaraman
DES is now used. Triple DES applies the DES algorithm thrice each time with a different 56-
bit key and is expected to be secure in the foreseeable future. As triple DES is an application
of DES thrice, the same DES chips technology can be used for its hardware implementation.
A new standard has been developed called Advanced Encryption Standard (AES), which uses
128-bit blocks and 128- or 192- or 256-bit keys (depending on the level of security specified)
(Landau 2000; Daeman & Rijmen 2002), but is not yet widely used.
The encryption methods we have discussed so far are called symmetric key or private key
encryption as encryption and decryption use the same key known to the two parties exchanging
messages. The main problems with this method are the need to have a separate key for each
of the organizations with which an organization transacts business and the requirement to
securely distribute the keys to all of them. Key distribution must use a different channel to
avoid it being stolen. Further, one needs to maintain a table of all keys and keep it secure from
snoopers.
M2 when hashed should give unique hashed values H1 and H2. H should also be much
shorter compared to M. Hashing is done primarily to reduce the size of the signature. (A
hashing method called MD5 (Message Digest 5) is popular.) Also hashing the message
M ties H to M. In other words, the signature uses H, which is tied to the document being
sent.
(7) H is encrypted by S using his private key and transmitted to R. This is his digital signature
DS.
(8) As R already has M he can hash it using the known hash function to obtain H.
(9) When R receives DS, he decrypts it using the public key of the sender S.
(10) The decrypted value must be H. If it is not, then it is a fake message. If it is H then
R is convinced that it is signed by S. S cannot repudiate (i.e. say that he did not send
the message) as he has encrypted H using his private key which is known only to
him.
The procedure works because the RSA algorithm is symmetric, i.e., if encryption is done
with a private key decryption can be done with the corresponding public key.
The second question we raised at the beginning of this section was about the authenticity
of public keys. This is done by some organizations (identified by governments) which issue
public key certificates after verifying the credentials of an organization or individual. Thus,
if an organization A wants to do business with another organization B electronically, B
can send an email to the certification authority requesting certification of A’s public key,
email identity etc. Once the certifying authority certifies the public key, transactions can
proceed. The certification authority takes on the legal responsibility in case of disputes on
identity.
Building blocks of e-commerce 103
7. Middleman services
(3) A purchase invoice, coupled with the credit card number, is digitally signed by the customer
so that disputes, if any, on purchase invoice and cost can be settled by an arbitrator.
The complete protocol is given in detail in a formal SET protocol definition. We will present
the simplified essentials of the protocol in what follows. Readers interested in learning about
the detailed protocol are referred to Stallings (1999) in the suggested reading list and the
website [Link]/SG244978.
obtain POA. CCD and DS are also sent to him separately. Remember that given CCD he
cannot find CCA as hashing is a one way function. Thus, credit card number is not available
to the merchant. The merchant can compute
H(H(POA)||CCD) = H(POD||CCD). (2)
The signature DS received by the merchant can be decrypted by him using the public key of
the customer to obtain,
CPUK (DS), (3)
where CPUK is the certified public key of the customer which is sent to the merchant by the
customer along with his purchase order. If (2) equals (3), then the merchant has verified the
customer’s signature. If payment is authorized by the acquirer, he can ship the order.
As far as the bank is concerned, it receives the CCA encrypted by the customer with the
bank’s public key forwarded by the acquirer. It can decrypt it using its private key and obtain
the CCA. The bank also receives POD and DS. Remember that POA cannot be found from
POD as it is obtained by hashing POA with a one-way hash function. The bank will not thus
know the purchase details. It can however compute
H(POD||H(CCA)) = H(POD||CCD), (4)
and CPUK (DS). If (4) equals CPUK (DS), the signature of the customer is verified by the bank.
If the customer’s balance in the credit card account is adequate, the bank can authorise the
merchant to honour the purchase order.
Observe that the customer cannot repudiate his purchase order as it has been signed by him
and deposited with the bank. The merchant also cannot substitute a customer’s purchase order
with some other purchase order as the signature contains a unique digest of the customer’s
purchase order as deposited with the bank.
We summarise the procedure below.
Step 1: Customer fills purchase order, amount payable and credit card number in his PC. A
software in the PC strips it into two parts: purchase order with amount and credit card
number with amount. Let us call them POA and CCA.
POA is encrypted using the merchant’s public key and CCA with the bank’s public
key. Both are sent to the merchant along with CCD and dual signature (DS). Merchant
verifies signature and proceeds further if signature is OK.
Step 2: Merchant forwards encrypted CCA, POD and DS to acquirer who forwards it to
customer’s bank.
Step 3: The bank decrypts CCA with its private key, checks the validity of the credit card
and available balance in the credit card account. If it is OK and the customer’s digital
signature is OK it authorises the acquirer the to proceed with the transaction.
Step 4: The acquirer in turn okays the transaction to the merchant and credits his account.
Step 5: The merchant accepts the customer’s purchase order and informs him about delivery
details.
Step 6: At the end of the month, the bank issuing the credit card sends a consolidated bill to
the customer.
It should be remembered that all the operations are carried out by software stored in the
respective computers and effected by clicks of their mouse buttons!
106 V Rajaraman
Step 1: A purchaser fills a purchase order form, attaches a payment advice (electronic
cheque), signs it with his private key (using his signature hardware), attaches his
public key certificate, encrypts it using the vendor’s public key and sends it to the
vendor.
Step 2: The vendor decrypts the information using his private key, checks the purchaser’s
certificates, signature and cheque, attaches his deposit slip, and endorses the
deposit attaching his public key certificates. This is encrypted and sent to his
bank.
Step 3: The vendor’s bank checks the signatures and certificates and sends the cheque
for clearance. The banks and clearing house normally have a private secure data
network.
Building blocks of e-commerce 107
Step 4: When the cheque is cleared, the amount is credited to the vendor’s account and a
credit advice is sent to him.
Step 5: The purchaser gets a consolidated debit advice periodically.
We have not described the signing process in detail as it has been described already.
Communications between customer, vendor and the bank are also encrypted as the internet
is used. As the amounts involved are small, symmetric cryptography is used for these com-
munications as it is faster. There are two points which need clarification. The first is the cost
of servicing e-coins. Normally banks charge a small commission for the service from ven-
dors. The second is whether a vendor who receives an e-coin from a customer can use it to
purchase goods from another vendor. This is not possible as the issuing bank has to authen-
ticate the e-coin and, while doing it, it has marked the coin as “spent”. Thus, it is not really
like good old cash!
The simple protocol used above does not preserve the anonymity of cash. The bank will
know which customer and vendor are involved in the cash transaction and can link the two.
There is another protocol called “transaction blinding” in which it is possible for a customer
to get e-coins issued by a bank without revealing his identity. The protocol called Chaum’s
blinding protocol is complicated and, as of now, is not used widely. Chaum invented the idea
of blinding (Chaum 1992).
We now describe the steps a business A should follow to establish an EDI partnership with
business B (figure 10).
(1) The first step is to agree on a standard format for commonly used documents such as
purchase orders, invoices, payment advices, delivery notes etc. Formatting information
or data type definition, as it is called, should include description of various fields used
such as quantities, price, currency used, delivery date, field lengths, character type, order-
ing of fields in the document, units used etc. As companies may transact business with
many partners, it is desirable to have a universally agreed standard form for all business
documents. This realisation led to industry groups such as the automobile industry, ship-
ping and transport industry to adopt standards for inter-company transactions. This later
evolved into national and international standards. The two standards are ANSI X.12 stan-
dard adopted by the American National Standards Institute for electronic transactions in
the United States of America and EDIFACT (Electronic Data Interchange For Adminis-
tration, Commerce and Transport) standardised by the United Nations Economic Com-
mission for Europe.
(2) Once an EDI standard is agreed on, company A should send business documents to com-
pany B using this format. This would require translation of company A’s documents such
as purchase order to the EDI format. The EDI messages are text with special characters
such as ‘ , + and : as field separators. There are special tags defined in the EDIFACT
dictionary for message header, date etc. The EDI message is meant to be interpreted by
computer programs and is thus not easily understood by people unless they are trained in
understanding the standard. A purchase order for a book using the EDIFACT standard is
given in table 2. In fact EDIFACT standard defines several hundred transaction sets for
various types of transactions between organizations and it requires an expert to understand
it and convert commonly used documents (which are meant for people to understand) to
EDIFACT form using a program.
(3) The last decision to be taken is how the data is to be exchanged between the participating
businesses. There are three alternatives. One can use the internet or extranet or a Value-
Added Network provided by some vendors for reliable, secure communications of business
data among participating businesses.
Extranet also uses the same method as internet as the protocol used in extranet is also
TCP/IP. The main difference is better security as it is more difficult for hackers to enter an
extranet which is a private network or a Virtual Private Network (VPN) connecting cooperating
businesses.
Value-added networks (VAN) are private networks (see figure 11) maintained by vendors
such as IBM info exchange and General Electric Infoserver which provide EDI services to
its customers. VANs provide post boxes for each of its subscribers who want to use their ser-
vices. A sender wanting to send, say a purchase order, addresses it to a vendor and deposits
it in a “postbox” maintained by VAN. The VAN service software receives this, converts it to
the required EDI standard format (if requested) and deposits it in a post box which has the
recipients’ address. VANs operate 24 hours a day, 7 days a week. They have back-up systems
to provide fail-safe operations. VANs guarantee delivery of EDI messages, provide acknowl-
edgement to senders, ensure security of messages, and audit trails and non-repudiation. Logs
of all activities are maintained and backed up for a reasonable length of time to ensure an
effective dispute settlement mechanism. Despite all these services offered by VAN, they have
not been popular primarily due to their high cost. Only larger businesses can afford to use
their services. Internet-based EDI, on the other hand, is relatively inexpensive. It also pro-
vides connections to all businesses large and small. Businesses have also found it expensive
to implement ANSI X.12 or EDIFACT standard as they are quite complex to learn and use.
Thus, fewer than 15% of businesses using e-commerce for their transactions have adopted the
EDIFACT/ANSI standards for EDI. Further, EDIFACT as well as ANSI X.12 EDI standards
are low-level machine-oriented documents. They were developed almost 25 years ago when
networks were slow and processors also were slow. With the emergence of networks which
can transfer data at the rate of gigabits/second and processors with 2GHz clocks, speed is no
more a concern. Currently, the major concern is to enable all businesses, big and small, to par-
ticipate in B2B e-commerce cost effectively. Electronic business documents to be exchanged
must have flexible structures as businesses find it impossible to adhere to a common format as
they have been using their own business documents for a long time and are reluctant to change
their formats as it involves expensive redesign of systems and also the retraining of people.
Now-a-days firms across the world transact business with one another. Each country has its
own taxation structure, rules and regulations and to expect all firms to adopt a common stan-
dard for all business documents is unrealistic. This is the main reason why EDI standards such
as EDIFACT and ANSI X.12 are not widely used. This has led to the development of XML
(EXtended Markup Language) for describing business documents. We discuss this next.
(1) XML can be used to define the format, and layout of multimedia documents on a web
page. It allows use of hyper-links and is thus a good language to design web pages. As
it follows a stricter syntax compared to HTML, it is easier to design browsers to retrieve
and view XML documents compared to HTML documents.
(2) Tags used in XML are user-defined and are usually meaningful. Thus users can understand
the nature of the document.
(3) XML has the capability to enforce a common structure for large documents which sim-
plifies editing. The emphasis of structure in XML ensures better stability of documents.
(4) Use of XML simplifies EDI, as XML can define the structure, syntax and semantics of
documents. It also supports extending and changing the documents if necessary.
(5) As an XML document structure is clearly defined, it is possible to write a program to
retrieve contents of fields such as item code, quantity ordered, price per unit etc., from a
document such as an invoice received electronically, and use it in an application.
In figure 12 we have given the EDI document defined in table 2 using XML. Observe
how easily the XML description can be read and understood. When a company uses XML
to describe business documents, it also gives a set of statements which define the syntax of
the XML program. This is called a document type definition (DTD). This is published in the
112 V Rajaraman
Figure 12. XML definition of book purchase order given in table 2 in EDIFACT notation.
company’s website so that any application program wanting to use the XML document can
download and interpret the XML document correctly. The DTD corresponding to the XML
description of figure 12 is given in figure 13. In this definition #PCDATA means that the
element contains a text. There are other key words used in DTD, which we will not discuss
in this article. A reference to where the DTD is available (e.g. a file name) should be given
at the beginning, as in the XML program of figure 12. The two statements which should be
placed at the beginning of the XML program of figure 12 are given in figure 14. It is assumed
that the file [Link] contains the DTD of order.
For details of XML and its application in web design and EDI the reader should read
Maruyama et al (2000) and Marchal (2001).
We have given a very brief overview of EDI in this article. Those interested in e-commerce
must have a good knowledge of XML and Java as Java is used to access XML documents and
process data using it. Apart from EDI, e-commerce also requires publication of price lists on
a company’s web page, business forms to be filled by customers which are made available on-
line and managing customer relations (such as attending to information request, complaints,
suggestions, etc.) All these also require use of XML which is more flexible than HTML.
So far we described the evolution of e-commerce and some of the technologies crucial in its
development. The area of e-commerce is very young and dynamic. Not only has it introduced
Building blocks of e-commerce 113
new technologies but has also brought in its wake a number of new social and legal issues.
In this section we describe some of the emerging technologies. We also discuss some aspects
of the information technology act passed by our parliament in 2000 (Duggal 2000) whose
primary purpose is to promote e-commerce and e-governance. We first briefly describe mobile
commerce, commonly known as m-commerce.
broadcasts its unique identity code. With the help of a cellular wireless infrastructure, its loca-
tion can be found. One can use this to trace packages and inform customers when they can
expect to receive a package. This information can also be used to reroute a package where it
is critically needed.
Another application is to inform a chemist or a hospital about expiry dates of drugs in
their inventory. This is done by embedding a small wireless device (called a radio frequency
identification tag) in the packing of expensive drugs which have a short life. These packets
broadcast their status once a day which is monitored by a server in the shop or hospital
and appropriate action is initiated. An emerging application is to provide information on
delays in flight schedules, traffic jam reports etc., to mobile users. Mobile commerce is
also used for providing to customers who are in transit, information on nearby stores which
have an item they need and also comparative prices to let them decide where they want to
shop.
(1) E-mail correspondence has legal status and thus can be used in evidence. Digitally signed
documents are now recognized.
(2) A controller of public key-certifying authorities has been appointed by the Government
of India. The controller recognizes certifying authorities who will have the authority to
issue public key certificates and verify digital signatures.
(3) All applications to Government bodies can be filed in electronic form. Government can
issue licences, permits, sanctions, approvals etc., online, in electronic form.
(4) Many archival documents which companies and government departments are required,
by law, to keep for a specified period can now be stored in CD-ROM or tapes, saving
precious space and enabling easy retrieval. Care must be taken that such electronically
stored documents also keep details which identifies the origin of the document, date and
time of despatch or receipt.
(5) The IT Act provides statutory remedy to companies whose networks are illegally accessed
and stored information is stolen or damaged. Monetary claims up to one crore of rupees
can be made against intruders.
The Act provides for punishment to a hacker who
(i) downloads, copies or extracts data from a database without permission of the owner,
(ii) introduces any soft-contaminant or computer virus into any computer or computer
network,
(iii) damages programs or data residing in a computer or network or illegally copies them,
(iv) disrupts a computer or network,
(v) denies access to a computer or a network by authorised persons,
(vi) charges for services availed of by a person to another person by tampering or manip-
ulating accounts in a computer or network.
Hacking has now been classified as a crime under the Indian Penal Code. Punishment
for hacking is imprisonment of up to 3 years or fine up to Rs. 2 lakhs or both. Teenagers
who hack “for fun” should realise that they will have fun in jail up to 3 years!
Even though the IT Act has a number of laudatory features it still has some flaws as
listed below.
(i) It is not clear how cyber crimes affecting computers in India committed from outside
India using the internet will be handled;
116 V Rajaraman
(ii) It is not clear how many of the provisions in the Act will be enforceable;
(iii) The Act does not apply to a number of important legal documents, such as a power
of attorney, a will, any contract for the sale of immovable property and a negotiable
instrument;
(iv) The Act does not have any provision regarding domain names and resolving disputes
on such names;
(v) It does not deal with intellectual property rights, trademarks and patents;
(vi) Many cyber crimes are not defined in the Act such as cyber defamation, cyber harass-
ment and cyber stalking;
(vii) Statutory bodies may at their discretion not accept electronic documents. In other
words a person cannot insist that he/she will submit only an electronic document.
Besides the above, there are some aspects of privacy and individual freedom, which these
laws dilute by giving enormous power to the executive. For instance, it allows any agency of
the government to intercept any information transmitted through any computer resource, if
the same is necessary in the interest of the sovereignty or integrity of India, the security of the
state, friendly relations with foreign governments, maintaining public order or for preventing
incitement to commit a cognizable offence. Another draconian provision is the powers given
to police officers not below the rank of a Deputy Superintendent of Police to enter any public
place and search and arrest without warrant any person found therein, who is reasonably
suspected of having committed or of committing or of being about to commit any offence
under the IT Act. This provision is supposed to prevent software piracy and hacking but has
enormous scope for harassment.
It is heartening to note that India is one of the few countries in the world which now has
an IT law in place even though it is not “perfect”. This is expected to boost e-commerce in
the country.
9. Conclusion
Electronic commerce is rapidly growing in the world and is expanding into what is known
as e-services (Stafford 2003). A number of technologies have converged to facilitate the
proliferation of e-commerce. Rapid advances in computer technology exemplified by the
availability of very powerful personal computers at low cost, coupled with rapid acceleration
in communication networks, have enabled computers worldwide to be interconnected and thus
have revolutionized the way business is done. The mere availability of hardware infrastructure
is not sufficient to proliferate applications. We require several software layers on the basic
hardware and international standards to promote applications such as e-commerce. In this
article, we have given a flavour of these software systems which constitute the building
blocks of e-commerce. Even though technology is essential to enable the emergence of e-
commerce it is not sufficient to promote and proliferate e-commerce applications. We need an
appropriate legal framework. We have thus discussed the enabling legal framework which has
been enacted in India. In the age of internet, national boundaries are becoming meaningless.
Data can travel at the speed of light across national boundaries; they can flow not only along
wired networks but also by wireless. Governments find it very difficult to stop data flow.
Applicability of national laws in international e-commerce has become impractical. This is
exemplified particularly by the emergence of vandals who disrupt the internet by proliferating
Building blocks of e-commerce 117
viruses, worms etc., which affect all countries. International cooperation in standardization
of not only technology but also laws is needed. It is evident that the cost of doing business has
come down and the reach of business has increased with the emergence of e-commerce. With
international cooperation, e-commerce is bound to improve the quality of life of individuals
all over the world.
References