0% found this document useful (0 votes)
7 views23 pages

E-Commerce Network Infrastructure Guide

Uploaded by

Arab Suzan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views23 pages

E-Commerce Network Infrastructure Guide

Uploaded by

Arab Suzan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

2022

Unit-02

Network Infrastructure and security


By: RUvanshi Sarang

Iqra Bca Collge | Dahegam-Bharuch


Network Infrastructure for E-Commerce
Broadband?
▪ A high-capacity transmission technique using a wide range of frequencies,
which enables a large number of messages to be communicated
simultaneously.
▪ Broadband commonly refers to Internet access via a variety of high-speed
wired and wireless networks, including cable, DSL, FiOS (Fiber Optic Strands),
Wi-Fi, WiMAX, 3G, 4G and satellite, all of which are faster than earlier analog
dial-up by a huge magnitude.

I-Way:
Definition
▪ Information Superhighway is a high-speed global communications network
that can carry data, voice, video and other services around the world using
technology such as the satellite, optical fiber and cellular telecommunications.
▪ Basically, the term I-way describes a high-capacity (broadband), interactive
(two-way) electronic pipeline to the home or office that is capable of
simultaneously supporting a large number of electronic commerce applications
and providing interactive connectivity between users and services and
between users and other users.
▪ It is envisioned to provide very high-speed access to information in all forms
(text, graphics, audio, video) via a wired or wireless connection.

Introduction to I-Way
▪ The information superhighway is a term coined by American Vice President
Albert Gore when giving a speech on January 11, 1994 describing the future of
computers accessing and communicating over a world-wide network.
▪ In simple words, it is the global information and communications network
that includes the Internet and other networks and switching systems such as
telephone networks, cable television networks, and satellite communication
networks used for e-commerce and many more other purposes.
▪ The I-way has emerged as the basic network infrastructure for all types of E-
commerce activities due to its capability to provide integrated voice ,data and
video services .
▪ I-way has changed the way business advertises, market or sell their products
and services.
▪ A physical network, an infrastructure of modern high-speed that links
everyone at home or office to everything else.
▪ In practicality it is identical to internet provided -connections are broadband -
they are continuously running.
▪ As internet develops into I-way, changes will take place in infrastructure not
in internet.
Market Forces Influencing I-Way
▪ Users: becoming information publishers.
▪ Consumers, end users, or businesses: consuming information about
products/services.
▪ ISPs: commercial, government or private.
▪ Value added information providers: includes third party brokers,
intermediaries, originators of services who add value to services provided by
others.

Components of I-Way
Components of I-Way: Network access equipment
This component of the I-way includes hardware and software vendors, who
provide physical devices such as routers and switches, access devices such as
computers and set-top boxes, and software platforms such as browsers and
operating systems.
 Hardware and software vendors: who provide
o set-top boxes
o computers
o switches, hubs, routers
o software platforms such as browser operating systems
Components of I-Way: Local on-ramps or access roads
▪ Simplify linkages between businesses, schools, and homes to the
communications backbone.
▪ This component is often called the "last mile" in the telecommunications
industry.
▪ The providers of access ramps can be differentiated into four categories:
 telecom-based,
 cable TV—based,
 wireless-based, and
 computer-based on-line information services that include value-added
networks (VANs) like intranet of an enterprise.

LOCAL ON-RAMPS: Simplified


▪ connections linking home and personal networks with backbone
▪ requirement of huge investment
▪ also known as “last mile”
▪ divided into four categories:
1. telecom-based infrastructure
2. cable tv-based infrastructure
3. wireless infrastructure
4. commercial online infrastructure(internet)
Components of I-Way: Global information distribution network

▪ Represent the communication infrastructure crisscrossing countries and


continents. (i.e. long distance network)
▪ Most of the infrastructure for the I-way already exists in the vast network of
fiber optic strands, coaxial cables, radio waves, satellites, and copper wires
spanning the globe.
▪ Linking all the components of the I-way will require large capital investments
in "open" systems (interoperable equipment that uses common standards) and
installing gateways between various networks.
▪ A final requirement is switching hardware and software to move huge
amounts of data effortlessly over such a complex network.

Transaction Models
E-commerce business models can generally be categorized into the following
categories.
 Business - to - Business (B2B)
 Business - to - Consumer (B2C)
 Consumer - to - Consumer (C2C)
 Consumer - to - Business (C2B)
 Business - to - Government (B2G)
 Government - to - Business (G2B)
 Government - to - Citizen (G2C)

Business - to - Government
B2G model is a variant of B2B model. Such websites are used by governments
to trade and exchange information with various business organizations. Such
websites are accredited by the government and provide a medium to
businesses to submit application forms to the government.
Government - to - Business
Governments use B2G model websites to approach business organizations.
Such websites support auctions, tenders, and application submission
functionalities.

Government - to - Citizen
Governments use G2C model websites to approach citizen in general. Such
websites support auctions of vehicles, machinery, or any other material. Such
website also provides services like registration for birth, marriage or death
certificates. The main objective of G2C websites is to reduce the average time
for fulfilling citizen’s requests for various government services.
E-Commerce - Payment Systems
 E-commerce sites use electronic payment, where electronic payment
refers to paperless monetary transactions. Electronic payment has
revolutionized the business processing by reducing the paperwork,
transaction costs, and labor cost. Being user friendly and less time-
consuming than manual processing, it helps business organization to
expand its market reach/expansion.
Listed below are some of the modes of electronic payments −
 Credit Card
 Debit Card
 Smart Card
 E-Money
 Electronic Fund Transfer (EFT)

Credit Card
 Payment using credit card is one of most common mode of electronic
payment.
 Credit card is small plastic card with a unique number attached with an
account.

 It has also a magnetic strip embedded in it which is used to read credit


card via card readers.
 When a customer purchases a product via credit card, credit card issuer
bank pays on behalf of the customer and customer has a certain time
period after which he/she can pay the credit card bill.
It is usually credit card monthly payment cycle. Following are the actors in the
credit card system.
 The card holder − Customer
 The merchant − seller of product who can accept credit card payments.
 The card issuer bank − card holder's bank
 The acquirer bank − the merchant's bank
 The card brand − for example, visa or Mastercard.

Debit Card
 Debit card, like credit card, is a small plastic card with a unique number
mapped with the bank account number.
 It is required to have a bank account before getting a debit card from the
bank.

 The major difference between a debit card and a credit card is that in
case of payment through debit card, the amount gets deducted from the
card's bank account immediately and there should be sufficient balance
in the bank account for the transaction to get completed; whereas in
case of a credit card transaction, there is no such compulsion.

 Debit cards free the customer to carry cash and cheques. Even
merchants accept a debit card readily. Having a restriction on the
amount that can be withdrawn in a day using a debit card helps the
customer to keep a check on his/her spending.

Smart Card
 Smart card is again similar to a credit card or a debit card in appearance,
but it has a small microprocessor chip embedded in it.
 It has the capacity to store a customer’s work-related and/or personal
information. Smart cards are also used to store money and the amount
gets deducted after every transaction.

 Smart cards can only be accessed using a PIN that every customer is
assigned with. Smart cards are secure, as they store information in
encrypted format and are less expensive/provides faster processing.
Mondex and Visa Cash cards are examples of smart cards.

E-Money
 E-Money transactions refer to situation where payment is done over the
network and the amount gets transferred from one financial body to
another financial body without any involvement of a middleman.
 E-money transactions are faster, convenient, and saves a lot of time.
 Online payments done via credit cards, debit cards, or smart cards are
examples of e-money transactions. Another popular example is e-cash.
 In case of e-cash, both customer and merchant have to sign up with the
bank or company issuing e-cash.

Electronic Fund Transfer


 It is a very popular electronic payment method to transfer money from
one bank account to another bank account. Accounts can be in the same
bank or different banks. Fund transfer can be done using ATM
(Automated Teller Machine) or using a computer.
 Nowadays, internet-based EFT is getting popular. In this case, a customer
uses the website provided by the bank, logs in to the bank's website and
registers another bank account.
 He/she then places a request to transfer certain amount to that account.
Customer's bank transfers the amount to other account if it is in the
same bank, otherwise the transfer request is forwarded to an ACH
(Automated Clearing House) to transfer the amount to other account
and the amount is deducted from the customer's account.
 Once the amount is transferred to other account, the customer is
notified of the fund transfer by the bank.

What is the Electronic Fund Transfer Process?


An EFT transfer is usually very straight forward. There are two parties: the
sender of funds, and the receiver of funds. Once the sender initiates the
transfer, the request channels through a series of digital networks originating
from either the internet or a payment terminal, to the sender’s bank, and then
to the receiver’s bank. Senders can be anyone from an employer, to a business,
to an individual paying a vendor for a service such as electricity. Likewise,
recipients can be entities like employees, goods suppliers, retailers, and utility
companies. Most payments are cleared, that is complete, within a couple days.

Types of EFT Payments


FT payment methods vary. Every method of EFT offers ease and fast delivery,
which is why it’s become so popular. While EFT is preferred worldwide, it’s
important to know the various ways one can take part in EFT payments. Here
are the most common types of EFT:

Electronic Checks
In this payment, a digital check is generated upon the payer’s authorization. E-
checks are commonly used for vendor payments.

Direct Deposit
With direct deposit, funds are automatically deposited into an account with
little to no paperwork. This method is popular among employees. While the
automatic deposit requires almost no work on a regular basis, the deposit
needs to be set up, and this requires bank account information for the
recipient, among other potential information for entry.

Phone Payments
This is a casual transaction, and it occurs during a phone call. Usually the payee
will supply their information, typically a card number, to the recipient over the
phone. The transaction will happen on the recipient’s line. The payee does very
little after verbal authorization. This is common for utility payments.

ATM Transactions
A global convenience, ATM transactions occur at electronic kiosks found
throughout cities and banks all over the world. In this case, a person is
withdrawing cash from their bank account by inserting their debit card into a
machine, which will transmit information to the bank, and then process the
request to dispense money. It is an instant transaction.

Card Transactions
During the point of sale phase of a transaction, a credit card or debit card is the
most commonly used form of payment around the world, replacing cash. This
can be in person or online, and entails the swipe, dip, or entry of a card, during
which account information is electronically received and a payment
withdrawal is approved, then the payment is scheduled and processed within a
day or two.
Internet Transactions
The internet version of tapping, swiping, or inserting a card involves manual
entry into a point of sale field, followed by clicking a payment button. This
process does the same as the above, processing an approval for payment, and
then transferring funds for payment within a couple days.

Other Payment System:


E-Cash
In its simplest form, eCash can be defined as electronic cash. It's a way of
paying for goods and services that isn’t in physical cash. There are two forms of
eCash, an online form and an offline form.

1. Online eCash
The term eCash was originally used by a company called DigiCash, founded by
David Chaum. DigiCash went bankrupt in 1998. The idea of eCash, however,
lived on. It was the idea that started online transactions, as well as
cryptocurrency.
It worked for all types of transactions.
With online eCash, information regarding currency is downloaded to a hard
drive. It stays there until it is transferred to another person or business online.
This is the basis of cryptocurrency, in a very simple way.

2. Offline eCash
The idea behind offline eCash has its roots in credit cards and debit cards.
Offline eCash would function similarly to a debit card. Funds from a hard drive
would be linked to a digitally encoded card.
This card would replace paper money (like a debit card). However, the main
difference here is that physical money no longer exists to begin with. With a
debit card, physical money is still present, in a way.

Note: when you have an electronic payment instrument that you can use to
pay a merchant, then that’s "e-money", but when you have an electronic
payment instrument that can be used to pay another person, then that’s "e-
cash".

E-wallets:
E-wallets act just like physical wallets except that all the cards and money are
virtually stored. They help with instant payments and quick checkouts while
purchasing on the internet.
The estimated value of mobile wallet transactions in the financial year 2021
across India was over 1.5 trillion Indian rupees. Rising smartphone penetration
along with increasing competition in the domestic market can be attributed to
the growing value.
E-wallets are fairly advanced versions of e payments and users can add money
to their wallets through credit/debit cards, net banking or using UPI.
India has seen a rise in the number of e-wallet companies offering incentives to
their users such as cashbacks and discounts to encourage them to transact
more and more through e-wallets.

Mobile wallet – An evolved form of e-wallet, mobile wallet is extensively used


by lots of customers.
It is a virtual wallet, in the form of an app that sits on a mobile device. Mobile
wallet stores card information on a mobile device.
The user-friendly nature of mobile wallets makes them easier to use. It offers a
seamless payment experience making customers less dependent on cash.

Electronic Cheque
Electronic cheques address the electronic needs of millions of businesses,
which today exchange traditional paper cheques with the other vendors,
consumers and government.
The e-cheque method was deliberately created to work in much the same way
as conventional paper cheque.
An account holder will issue an electronic document that contains the
name of the financial institution, the payer’s account number, the
name of payee and amount of cheque.
Most of the information is in uncoded form. Like a paper cheques e-
cheques also bear the digital equivalent of signature: a computed
number that authenticates the cheque from the owner of the account.
Digital chequing payment system seeks to extend the functionality of existing
chequing accounts for use as online shopping payment tools.
Risk in Electronic Payment System

Payment conflict
 Payment conflict often arise because payments are not done manually
but done by an automated system that can cause error.
 This is especially common when payment is done on a regular basis to
many recipients
Impulse buying
 Impulse buying means – sudden buying
 e-payment systems encourage impulse buying, especially online.
 Impulse buying leads to disorganized budgets.
Dishonest merchants and financial providers
 Sometimes, some ecommerce websites are fake and if the customers do
any transaction from that website, then it becomes a fraudulent activity
for that customer.
 There are fake merchants who provoke the customers to buy the goods.
Stolen payment credentials and passwords
 Sometimes whatever transaction takes place, it is not safe. There are
different modes of electronic mode like credit cards, debit card, e-cash
etc.
 There are highly chance of passwords being hacked by the middle men.
Lack of anonymity
 The information about all the transactions are stored in the database of
the payment system.
 Simply means the intelligence agency has an access to this information.

Security on web
Definition of Web Security
 Web security is a broad category of security solutions that protect your
users, devices, and wider network against internet-based cyberattacks—
malware, phishing, and more—that can lead to breaches and data loss.
 It reduces the security risk to your organization when your users
accidentally access malicious files and websites through some
combination of firewall inspection, intrusion prevention system (IPS)
scanning, sandboxing, URL filtering, and various other security and
access controls.
Security is an essential part of any transaction that takes place over the
internet. Customers will lose his/her faith in e-business if its security is
compromised. Following are the essential requirements for safe
e-payments/transactions −
 Confidentiality − Information should not be accessible to an
unauthorized person. It should not be intercepted during the
transmission.
 Integrity − Information should not be altered during its transmission
over the network.
 Availability − Information should be available wherever and whenever
required within a time limit specified.
 Authenticity − There should be a mechanism to authenticate a user
before giving him/her an access to the required information.
 Non-Repudiability − It is the protection against the denial of order or
denial of payment. Once a sender sends a message, the sender should
not be able to deny sending the message. Similarly, the recipient of
message should not be able to deny the receipt.
 Encryption − Information should be encrypted and decrypted only by an
authorized user.
 Auditability − Data should be recorded in such a way that it can be
audited for integrity requirements.
Measures to ensure Security
Major security measures are following −
 Encryption − It is a very effective and practical way to safeguard the data
being transmitted over the network. Sender of the information encrypts
the data using a secret code and only the specified receiver can decrypt
the data using the same or a different secret code.
 Digital Signature − Digital signature ensures the authenticity of the
information. A digital signature is an e-signature authenticated through
encryption and password.
 Security Certificates − Security certificate is a unique digital id used to
verify the identity of an individual website or user.

Security Protocols in Internet


 We will discuss here some of the popular protocols used over the
internet to ensure secured online transactions.
 SSL Protocol ,SHTTP , SHEN etc.

Secure Hypertext Transfer Protocol (SHTTP)


SHTTP extends the secure HTTP internet protocol with public key encryption,
authentication, and digital signature over the internet. Secure HTTP supports
multiple security mechanism, providing security to the end-users. SHTTP works
by negotiating encryption scheme types used between the client and the
server.
Secure Electronic Transaction
It is a secure protocol developed by MasterCard and Visa in collaboration.
Theoretically, it is the best security protocol. It has the following components −
 Card Holder's Digital Wallet Software − Digital Wallet allows the card
holder to make secure purchases online via point and click interface.
 Merchant Software − This software helps merchants to communicate
with potential customers and financial institutions in a secure manner.
 Payment Gateway Server Software − Payment gateway provides
automatic and standard payment process. It supports the process for
merchant's certificate request.
 Certificate Authority Software − This software is used by financial
institutions to issue digital certificates to card holders and merchants,
and to enable them to register their account agreements for secure
electronic commerce.

Secure Socket Layer (SSL)


It is the most commonly used protocol and is widely used across the industry.
It meets following security requirements −
 Authentication
 Encryption
 Integrity
 Non-reputability
"[Link] is to be used for HTTP URLs with SSL, where as "http:/" is to be used
for HTTP URLs without SSL.
Secure Socket Layer (SSL) provides security to the data that is transferred
between web browser and server. SSL encrypts the link between a web server
and a browser which ensures that all data passed between them remain
private and free from attack.
Secure Socket Layer Protocols:
 SSL record protocol
 Handshake protocol
 Change-cipher spec protocol
 Alert protocol
SSL Protocol Stack or Architectu:

SSL Record Protocol:


SSL Record provides two services to SSL connection.
 Confidentiality
 Message Integrity
In the SSL Record Protocol application data is divided into fragments. The
fragment is compressed and then encrypted MAC (Message Authentication
Code) generated by algorithms like SHA (Secure Hash Protocol) and MD5
(Message Digest) is appended. After that encryption of the data is done and in
last SSL header is appended to the data.
Handshake Protocol:
Handshake Protocol is used to establish sessions. This protocol allows the
client and server to authenticate each other by sending a series of messages to
each other. Handshake protocol uses four phases to complete its cycle.
 Phase-1: In Phase-1 both Client and Server send hello-packets to each
other. In this IP session, cipher suite and protocol version are exchanged
for security purposes.
 Phase-2: Server sends his certificate and Server-key-exchange. The
server end phase-2 by sending the Server-hello-end packet.
 Phase-3: In this phase, Client replies to the server by sending his
certificate and Client-exchange-key.
 Phase-4: In Phase-4 Change-cipher suite occurred and after this
Handshake Protocol ends.

Change-cipher Protocol:
This protocol uses the SSL record protocol. Unless Handshake Protocol is
completed, the SSL record Output will be in a pending state. After the
handshake protocol, the Pending state is converted into the current state.
Change-cipher protocol consists of a single message which is 1 byte in length
and can have only one value. This protocol’s purpose is to cause the pending
state to be copied into the current state.

Alert Protocol:
This protocol is used to convey SSL-related alerts to the peer entity. Each
message in this protocol contains 2 bytes.

Warning (level = 1):


This Alert has no impact on the connection between sender and
receiver. Some of them are:
Bad certificate: When the received certificate is corrupt.
No certificate: When an appropriate certificate is not available.
Certificate expired: When a certificate has expired.
Certificate unknown: When some other unspecified issue arose in processing
the certificate, rendering it unacceptable.
Close notify: It notifies that the sender will no longer send any messages in the
connection.

Fatal Error (level = 2):


This Alert breaks the connection between sender and receiver. The connection
will be stopped, cannot be resumed but can be restarted. Some of them are :
Handshake failure: When the sender is unable to negotiate an acceptable set
of security parameters given the options available.
Decompression failure: When the decompression function receives improper
input.
Illegal parameters: When a field is out of range or inconsistent with other
fields.
Bad record MAC: When an incorrect MAC was received.
Unexpected message: When an inappropriate message is received.
The second byte in the Alert protocol describes the error.
Silent Features of Secure Socket Layer:
 The advantage of this approach is that the service can be tailored to the
specific needs of the given application.
 Secure Socket Layer was originated by Netscape.
 SSL is designed to make use of TCP to provide reliable end-to-end secure
service.
 This is a two-layered protocol.
Versions of SSL:
SSL 1 – Never released due to high insecurity.
SSL 2 – Released in 1995.
SSL 3 – Released in 1996.
TLS 1.0 – Released in 1999.
TLS 1.1 – Released in 2006.
TLS 1.2 – Released in 2008.
TLS 1.3 – Released in 2018.

Common questions

Powered by AI

E-money transactions typically involve the transfer of funds from one financial institution to another over a network without the involvement of a middleman, making them faster and more convenient . In contrast, e-cash transactions require both customer and merchant to sign up with the institution issuing the e-cash, which may involve more setup and coordination. E-money is used for payments involving electronic payment instruments like credit and debit cards, whereas e-cash can be used for direct person-to-person payments, showcasing a significant functional distinction .

SSL ensures secure data transmission by encrypting the link between a web server and a browser, thus keeping data private and safe from attacks . The SSL handshake protocol involves four phases: Phase-1 entails both client and server exchanging 'hello' messages and cipher suites for security purposes; Phase-2 involves the server sending its certificate and key-exchange information; in Phase-3, the client responds with its certificate and key-exchange information; and Phase-4 includes the change-cipher suite which finalizes the session setup .

Security certificates act as unique digital IDs verifying the identity of websites or users, thus preventing unauthorized access . Digital signatures ensure the authenticity and integrity of the information by using encryption and password-based verification, preventing data tampering during transmission and ensuring the sender's authentication . Together, they create a trusted environment for electronic transactions by verifying identities and maintaining data integrity.

Key security measures include encryption, which safeguards data during network transmission; digital signatures, which authenticate information integrity; security certificates, which ensure identity verification; and the use of security protocols like SSL and SHTTP which provide end-to-end secure service . These measures are critical as they protect against unauthorized data access, alteration, and various cyberattacks, maintaining customer trust and compliance with legal standards for secure e-payments .

Challenges include risks of data interception, unauthorized access, and identity theft during electronic transactions due to vulnerabilities like password hacking or phishing attacks . Strategies to address these include employing encryption for data protection, using digital signatures for authenticity, implementing security certificates for identity verification, and adhering to security protocols such as SSL for secure communications. These strategies minimize security risks and enhance trustworthiness in e-payment systems .

Non-repudiability prevents parties from denying participation in transactions, ensuring accountability . It is crucial for e-commerce as it creates legal proof and reduces fraud-related disputes. In digital payment systems, non-repudiability is achieved through digital signatures and secure logging mechanisms that record transaction data comprehensively, making it impossible to deny transaction occurrence . Such mechanisms are integral for maintaining transparency and security, fostering user confidence in electronic payment processes.

Encryption secures data by transforming information into a coded format only readable by authorized parties, thus protecting data in transit from unauthorized access . Digital signatures complement encryption by providing a mechanism to verify the authenticity and integrity of electronic messages or documents. This is achieved by creating a unique digital verification linked to the sender's identity. The combination of encryption and digital signatures ensures that data remains secure, authentic, and tamper-proof during electronic payments .

Credit cards allow users to make purchases on credit, with payments due later within a billing cycle, and involve several parties such as card holder, merchant, card issuer, acquirer bank, and card brand . Debit cards immediately deduct funds from the user’s bank account at the point of sale, thereby requiring sufficient balance, and are highly accessible to customers and merchants . Smart cards, which are similar in size but equipped with microprocessor chips, store personal or work-related information and money, securely accessed via PINs, and enable faster processing . Each card serves distinct purposes and provides differing levels of convenience and security.

Online eCash laid foundational concepts for digital currencies by enabling electronic cash transactions without physical money . This innovation paved the way for modern cryptocurrencies, integrating digital, decentralized peer-to-peer exchanges free from central authority control. eCash's principle of storing currency info on digital platforms and conducting transactions over the internet directly inspired subsequent blockchain technologies and cryptocurrency developments, leading to new financial systems like Bitcoin .

EFT is widely used because it facilitates direct money transfers between bank accounts, offering convenience and speed, crucial for payroll and vendor payments . Unlike credit or debit card transactions, which involve intermediaries like card issuers, EFT operates via digital networks allowing direct bank-to-bank transactions without intermediaries, leading to reduced processing times . Different EFT methods like electronic checks and direct deposits cater to specific needs, broadening its application across various financial activities.

You might also like