MIS And E-BusinessUnit 412 min read
E-Commerce Tech & Infrastructure: Protocols, Security, and Backbone Systems
Unit 4 of MIS And E-Business explores the technical foundation of e-commerce, covering wireless communication standards (UMTS, LTE, 5G), hardware/software security layers (IDS/IPS, firewalls), infrastructure models (cloud vs. on-premise), and real-world deployment challenges like latency, scalability, and compliance (P
TAKEAWAYS:
- Wireless tech matters: UMTS (3G) vs. LTE (4G) vs. 5G differ in speed, latency, and use cases—eSewa’s mobile payments rely on LTE/5G for sub-second transactions, while Daraz’s logistics use UMTS for GPS tracking.
- Security is layered: Authentication (OAuth 2.0), authorization (role-based access), and availability (CDNs) are enforced via hardware (HSMs) and software (WAFs, IDS/IPS)—Nabil Bank’s online banking uses HSMs for encryption keys.
- Infrastructure trade-offs: Cloud (scalability) vs. on-premise (control) decide whether a startup like Himalayan Java uses AWS or a private server for inventory management.
- Malware isn’t just code: Social engineering (phishing emails) and non-technical attacks (e.g., fake Daraz customer service calls) cause 60% of breaches—always verify URLs and sender IDs.
- Protocols power e-commerce: HTTPS (TLS 1.3), FTP (for file transfers), and APIs (REST/GraphQL) enable seamless transactions—Khalti’s payment gateway uses REST APIs for real-time bank integration.
- Feasibility ≠ tech alone: A viable e-commerce project needs funding (crowdfunding, angel investors), compliance (PCI-DSS for payments), and user-centric design—Pathao’s success came from LTE-based ride-hailing APIs + driver incentives.
Core Technologies: The Backbone of E-Commerce
E-commerce relies on three pillars:
- Communication protocols (how data moves),
- Security frameworks (how data stays safe), and
- Infrastructure models (where data lives).
Let’s break each down with real-world examples and visuals.
1. Wireless Communication Technologies
Wireless networks enable mobile commerce (m-commerce), from Pathao’s ride requests to NTC’s fiber-to-the-home (FTTH). The key standards:
Comparison Table: UMTS vs. LTE vs. 5G
| Feature | UMTS (3G) | LTE (4G) | 5G |
|---|---|---|---|
| Speed | 384 Kbps–2 Mbps | 100 Mbps–1 Gbps | 1–10 Gbps |
| Latency | 100–200 ms | 10–50 ms | 1–10 ms |
| Use Case | SMS, basic browsing | HD streaming, mobile apps | AR/VR, autonomous vehicles |
| Nepal Adoption | Ncell’s old 3G network | NTC’s 4G (LTE-A) | Ncell’s 5G trials (2023) |
| Security | WPA2 | WPA3 + IPsec | End-to-end encryption |
Why it matters:
- eSewa’s mobile app uses LTE/5G to process payments in <500ms (critical for user experience).
- Daraz’s logistics relies on UMTS for GPS tracking of delivery trucks—slower but cheaper than 4G.
How Wireless Works: The OSI Model in Action
graph LR
A["User Device\n(Phone/Tablet)"] -->|"HTTP/HTTPS"| B["Mobile Network\n(LTE/5G Tower)"]
B -->|"IP Packets"| C["Core Network\n(NTC/Ncell Gateway)"]
C -->|"DNS Resolution"| D["Internet\n(Cloud Servers)"]
D -->|"Response"| C
C -->|"Data"| B
B -->|"Decrypted"| AKey Layers:
- Physical Layer: Antennas, radio waves (UMTS uses CDMA, LTE uses OFDM).
- Network Layer: IP routing (NTC’s routers handle millions of packets/sec).
- Application Layer: HTTPS (TLS 1.3) encrypts data—Khalti uses this for PCI-DSS compliance.
Worked Example: Pathao’s ride-hailing system
- User opens app → LTE/5G connects to Ncell’s tower.
- Request sent via REST API to Pathao’s cloud server (AWS).
- Server matches driver via geohashing (UMTS/GPS).
- Payment processed via Khalti API (HTTPS).
- Latency: <200ms (4G) vs. >500ms (3G) → 20% more bookings on 4G.
2. E-Commerce Security: Defense in Depth
Security isn’t a single tool—it’s a layered approach. The CIA Triad (Confidentiality, Integrity, Availability) guides all defenses.
The CIA Triad in Action
mindmap
root((CIA Triad))
Confidentiality
Encryption: AES-256 (Khalti uses this for card data)
Access Control: Role-Based (e.g., Daraz admin vs. customer)
Integrity
Hashing: SHA-256 (eSewa verifies transaction logs)
Digital Signatures: SSL/TLS certificates (Nabil Bank’s website)
Availability
Redundancy: CDNs (Google Cloud for Daraz)
DDoS Protection: Cloudflare (used by Himalayan Java)Hardware vs. Software Security
| Hardware | Software | Example in Nepal |
|---|---|---|
| HSM (Hardware Security Module) | WAF (Web Application Firewall) | Nabil Bank’s HSM stores encryption keys; WAF blocks SQLi attacks on their website. |
| Firewalls (Next-Gen) | IDS/IPS (Intrusion Detection/Prevention) | NTC’s core network uses Palo Alto firewalls + Snort IDS. |
| Biometric Scanners | Multi-Factor Auth (MFA) | eSewa’s fingerprint login (hardware) + OTP (software). |
Non-Technical Attacks (The Human Factor)
- Phishing: Fake "Daraz Customer Support" emails asking for login credentials.
- Social Engineering: Callers impersonating NTC technicians to steal Wi-Fi passwords.
- Insider Threats: A disgruntled employee leaking Himalayan Java’s supplier list.
How to Mitigate:
- Employee Training: Simulated phishing tests (e.g., KnowBe4 used by banks).
- Verification: Always check URLs (https://daraz.ne) and sender emails (no@daraz.com).
- Incident Response Plan: Nabil Bank’s CSIRT team responds to breaches in <1 hour.
3. Infrastructure Models: Cloud vs. On-Premise
| Model | Pros | Cons | Nepal Example |
|---|---|---|---|
| Cloud (AWS/Azure) | Scalable, pay-as-you-go, global reach | Vendor lock-in, compliance risks | Daraz (AWS), eSewa (Google Cloud) |
| On-Premise | Full control, no internet dependency | High cost, maintenance overhead | NTC’s legacy systems (private servers) |
| Hybrid | Best of both worlds | Complex setup | Nabil Bank (cloud for apps, on-premise for core banking) |
Worked Example: Why Daraz chose AWS
- Peak traffic: During Dashain sales, traffic spikes 500%.
- Solution: AWS Auto Scaling adds servers dynamically.
- Cost: Pay only for used capacity (vs. buying 100 servers upfront).
Cloud Security Checklist:
- Data Encryption: At rest (AES-256) and in transit (TLS 1.3).
- Access Control: IAM roles (e.g., Daraz developers can’t access financial data).
- Compliance: PCI-DSS for payments, GDPR for user data (if storing EU customers).
4. E-Commerce Website Design Criteria
A poorly designed site = abandoned carts. Key factors:
Mermaid: User Journey on an E-Commerce Site
flowchart TD
A["User Lands on Homepage\n(Daraz.ne)"] -->|"Searches 'iPhone 15'"| B["Product Page\n(Images, Reviews, Price, 360° View)"]
B -->|"Adds to Cart"| C["Cart Page\n(Real-time Stock Check)"]
C -->|"Proceeds"| D["Payment Gateway\n(Khalti/eSewa, 5G-optimized)"]
D -->|"Success"| E["Order Confirmation\n(SMS + WhatsApp)"]
E -->|"Issue?"| F["Support\n(Chatbot + Live Agent, 24/7)"]
F -->|"Resolved"| G["Review\n(Star Rating + Referral Discount)"]Enhanced user journey with Nepali e-commerce specifics (e.g., 360° product views, SMS confirmations).Critical Design Elements:
- Mobile-First: 60% of Daraz traffic is mobile—responsive design is mandatory.
- Load Time: <2 seconds (Google’s threshold)—Daraz uses CDNs (Cloudflare).
- Trust Signals:
- SSL certificate (🔒 in browser).
- Customer reviews (e.g., 4.8/5 on Daraz).
- Secure payment badges (Visa/Mastercard logos).
- Accessibility: Screen-reader support (WCAG compliance).
Case Study: Himalayan Java’s Website
- Problem: Slow load times in rural areas (UMTS networks).
- Solution:
- Edge caching (Cloudflare).
- Compressed images (WebP format).
- Result: 30% increase in orders from outside Kathmandu.
5. Evaluating E-Commerce Project Feasibility
Not all ideas work. Use this checklist before launching:
Feasibility Criteria
Funding Options for Graduates:
| Option | Pros | Cons | Nepal Example |
|---|---|---|---|
| Bootstrapping | Full control | Slow growth | Early Himalayan Java (self-funded) |
| Angel Investors | Fast cash, mentorship | Equity loss | Antariksh Jnawali (invested in Daraz) |
| Crowdfunding | Validates demand | Platform fees (e.g., Kickstarter) | Nepali startups use Ketto |
| Bank Loans | No equity loss | Collateral required | Nabil Bank’s SME loans for e-commerce |
Worked Example: Launching a Nepali Grocery Delivery App
- Technical Feasibility:
- Use Firebase (Google’s BaaS) for backend to avoid server costs.
- Partner with local kirana stores for inventory.
- Financial Plan:
- Seed funding: ₹500,000 from angel investors.
- Break-even: 18 months (based on Pathao’s growth curve).
- Legal:
- Register with DoICT for e-commerce license.
- Comply with Nepali Consumer Protection Act.
In the Real World
eSewa’s Payment Gateway
- Technology Used: LTE/5G for mobile transactions, TLS 1.3 for encryption, HSMs for key storage.
- Why It Works: Nepal’s 80% mobile penetration—eSewa processes ₹500M/month via mobile.
- Security: 3D Secure for credit cards, biometric auth for fingerprint logins.
Daraz’s Logistics Network
- Wireless Tech: UMTS for GPS tracking, LTE for real-time delivery updates.
- Infrastructure: AWS cloud for dynamic scaling during sales.
- Challenge: Last-mile delivery in Nepal’s terrain → Daraz uses local hubs (not direct cloud routes).
Nabil Bank’s Online Banking
- Security Layers:
- HSM for encryption keys.
- WAF to block SQL injection.
- MFA (OTP + biometrics).
- Real-World Impact: 95% of transactions are fraud-free due to multi-layered security.
- Security Layers:
Exam Tip
This unit is conceptual + applied. Expect:
- Definitions + Comparisons:
- "Differentiate UMTS and LTE" → Use the table above (speed, latency, use cases).
- "Explain IDS vs. IPS" → Draw the Mermaid diagram showing how they work together.
- Scenario-Based Questions:
- "How would you secure eSewa’s mobile app?" → Cover TLS 1.3, HSMs, MFA, and phishing training.
- "Why did Daraz choose AWS?" → Mention scalability, cost, and global reach.
- Case Study Analysis:
- "Analyze Pathao’s wireless tech" → Link LTE/5G latency to user satisfaction.
- Feasibility Plans:
- "Propose an e-commerce startup" → Include tech stack, funding, and compliance.
Common Mistakes to Avoid:
- Ignoring non-technical attacks (e.g., phishing)—20% of exam questions test this.
- Assuming all e-commerce is cloud-based—some use on-premise (e.g., NTC).
- Skipping real-world examples—always tie answers to Nepali companies (Daraz, eSewa, Nabil Bank).
Pro Tip:
- Memorize the CIA Triad (Confidentiality, Integrity, Availability) and link it to every security question.
- Practice drawing:
- Wireless protocol stacks (OSI model).
- Security layers (HSMs, WAFs, IDS/IPS).
- User journeys (e-commerce site flow).
Nabil Bank’s encryption key storage unit (Image: Alexander Klink, CC BY 3.0, via Wikimedia Commons)
Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 4.
Discussion
Loading…