CACS301 MIS And E-Business

MIS And E-BusinessUnit 412 min read

E-Commerce Tech & Infrastructure: Protocols, Security, and Backbone Systems

Unit 4 of MIS And E-Business explores the technical foundation of e-commerce, covering wireless communication standards (UMTS, LTE, 5G), hardware/software security layers (IDS/IPS, firewalls), infrastructure models (cloud vs. on-premise), and real-world deployment challenges like latency, scalability, and compliance (P

TAKEAWAYS:

  • Wireless tech matters: UMTS (3G) vs. LTE (4G) vs. 5G differ in speed, latency, and use cases—eSewa’s mobile payments rely on LTE/5G for sub-second transactions, while Daraz’s logistics use UMTS for GPS tracking.
  • Security is layered: Authentication (OAuth 2.0), authorization (role-based access), and availability (CDNs) are enforced via hardware (HSMs) and software (WAFs, IDS/IPS)—Nabil Bank’s online banking uses HSMs for encryption keys.
  • Infrastructure trade-offs: Cloud (scalability) vs. on-premise (control) decide whether a startup like Himalayan Java uses AWS or a private server for inventory management.
  • Malware isn’t just code: Social engineering (phishing emails) and non-technical attacks (e.g., fake Daraz customer service calls) cause 60% of breaches—always verify URLs and sender IDs.
  • Protocols power e-commerce: HTTPS (TLS 1.3), FTP (for file transfers), and APIs (REST/GraphQL) enable seamless transactions—Khalti’s payment gateway uses REST APIs for real-time bank integration.
  • Feasibility ≠ tech alone: A viable e-commerce project needs funding (crowdfunding, angel investors), compliance (PCI-DSS for payments), and user-centric design—Pathao’s success came from LTE-based ride-hailing APIs + driver incentives.

Core Technologies: The Backbone of E-Commerce

E-commerce relies on three pillars:

  1. Communication protocols (how data moves),
  2. Security frameworks (how data stays safe), and
  3. Infrastructure models (where data lives).
LTE/5G (eSewa)UMTS (Daraz Logistics)Fiber Optic Backbone (NTC)Network LayerHSM (Hardware Security Module)WAF (Web Application Firewall)GDPR Compliance (User Data)Security LayerAPIs (REST/gRPC)Microservices (Daraz’s Order System)Blockchain (Supply Chain)Application LayerE-Commerce Infrastructure
Hierarchical breakdown of Nepali e-commerce infrastructure layers.

Let’s break each down with real-world examples and visuals.


1. Wireless Communication Technologies

Wireless networks enable mobile commerce (m-commerce), from Pathao’s ride requests to NTC’s fiber-to-the-home (FTTH). The key standards:

Comparison Table: UMTS vs. LTE vs. 5G
Feature UMTS (3G) LTE (4G) 5G
Speed 384 Kbps–2 Mbps 100 Mbps–1 Gbps 1–10 Gbps
Latency 100–200 ms 10–50 ms 1–10 ms
Use Case SMS, basic browsing HD streaming, mobile apps AR/VR, autonomous vehicles
Nepal Adoption Ncell’s old 3G network NTC’s 4G (LTE-A) Ncell’s 5G trials (2023)
Security WPA2 WPA3 + IPsec End-to-end encryption

Why it matters:

  • eSewa’s mobile app uses LTE/5G to process payments in <500ms (critical for user experience).
  • Daraz’s logistics relies on UMTS for GPS tracking of delivery trucks—slower but cheaper than 4G.
How Wireless Works: The OSI Model in Action
graph LR
    A["User Device\n(Phone/Tablet)"] -->|"HTTP/HTTPS"| B["Mobile Network\n(LTE/5G Tower)"]
    B -->|"IP Packets"| C["Core Network\n(NTC/Ncell Gateway)"]
    C -->|"DNS Resolution"| D["Internet\n(Cloud Servers)"]
    D -->|"Response"| C
    C -->|"Data"| B
    B -->|"Decrypted"| A

Key Layers:

  • Physical Layer: Antennas, radio waves (UMTS uses CDMA, LTE uses OFDM).
  • Network Layer: IP routing (NTC’s routers handle millions of packets/sec).
  • Application Layer: HTTPS (TLS 1.3) encrypts data—Khalti uses this for PCI-DSS compliance.

Worked Example: Pathao’s ride-hailing system

  1. User opens app → LTE/5G connects to Ncell’s tower.
  2. Request sent via REST API to Pathao’s cloud server (AWS).
  3. Server matches driver via geohashing (UMTS/GPS).
  4. Payment processed via Khalti API (HTTPS).
  5. Latency: <200ms (4G) vs. >500ms (3G) → 20% more bookings on 4G.

2. E-Commerce Security: Defense in Depth

Security isn’t a single tool—it’s a layered approach. The CIA Triad (Confidentiality, Integrity, Availability) guides all defenses.

The CIA Triad in Action
mindmap
  root((CIA Triad))
    Confidentiality
      Encryption: AES-256 (Khalti uses this for card data)
      Access Control: Role-Based (e.g., Daraz admin vs. customer)
    Integrity
      Hashing: SHA-256 (eSewa verifies transaction logs)
      Digital Signatures: SSL/TLS certificates (Nabil Bank’s website)
    Availability
      Redundancy: CDNs (Google Cloud for Daraz)
      DDoS Protection: Cloudflare (used by Himalayan Java)
Hardware vs. Software Security
Hardware Software Example in Nepal
HSM (Hardware Security Module) WAF (Web Application Firewall) Nabil Bank’s HSM stores encryption keys; WAF blocks SQLi attacks on their website.
Firewalls (Next-Gen) IDS/IPS (Intrusion Detection/Prevention) NTC’s core network uses Palo Alto firewalls + Snort IDS.
Biometric Scanners Multi-Factor Auth (MFA) eSewa’s fingerprint login (hardware) + OTP (software).

Non-Technical Attacks (The Human Factor)

  • Phishing: Fake "Daraz Customer Support" emails asking for login credentials.
  • Social Engineering: Callers impersonating NTC technicians to steal Wi-Fi passwords.
  • Insider Threats: A disgruntled employee leaking Himalayan Java’s supplier list.

How to Mitigate:

  1. Employee Training: Simulated phishing tests (e.g., KnowBe4 used by banks).
  2. Verification: Always check URLs (https://daraz.ne) and sender emails (no@daraz.com).
  3. Incident Response Plan: Nabil Bank’s CSIRT team responds to breaches in <1 hour.

3. Infrastructure Models: Cloud vs. On-Premise

Model Pros Cons Nepal Example
Cloud (AWS/Azure) Scalable, pay-as-you-go, global reach Vendor lock-in, compliance risks Daraz (AWS), eSewa (Google Cloud)
On-Premise Full control, no internet dependency High cost, maintenance overhead NTC’s legacy systems (private servers)
Hybrid Best of both worlds Complex setup Nabil Bank (cloud for apps, on-premise for core banking)
00.250.50.751Cost (USD/year)0Scalability0Downtime Risk0Data Control0
Cost-scalability tradeoff for Daraz vs. a local Nepali shop’s infrastructure.

Worked Example: Why Daraz chose AWS

  • Peak traffic: During Dashain sales, traffic spikes 500%.
  • Solution: AWS Auto Scaling adds servers dynamically.
  • Cost: Pay only for used capacity (vs. buying 100 servers upfront).

Cloud Security Checklist:

  1. Data Encryption: At rest (AES-256) and in transit (TLS 1.3).
  2. Access Control: IAM roles (e.g., Daraz developers can’t access financial data).
  3. Compliance: PCI-DSS for payments, GDPR for user data (if storing EU customers).

4. E-Commerce Website Design Criteria

A poorly designed site = abandoned carts. Key factors:

Mermaid: User Journey on an E-Commerce Site
flowchart TD
    A["User Lands on Homepage\n(Daraz.ne)"] -->|"Searches 'iPhone 15'"| B["Product Page\n(Images, Reviews, Price, 360° View)"]
    B -->|"Adds to Cart"| C["Cart Page\n(Real-time Stock Check)"]
    C -->|"Proceeds"| D["Payment Gateway\n(Khalti/eSewa, 5G-optimized)"]
    D -->|"Success"| E["Order Confirmation\n(SMS + WhatsApp)"]
    E -->|"Issue?"| F["Support\n(Chatbot + Live Agent, 24/7)"]
    F -->|"Resolved"| G["Review\n(Star Rating + Referral Discount)"]
Enhanced user journey with Nepali e-commerce specifics (e.g., 360° product views, SMS confirmations).

Critical Design Elements:

  1. Mobile-First: 60% of Daraz traffic is mobile—responsive design is mandatory.
  2. Load Time: <2 seconds (Google’s threshold)—Daraz uses CDNs (Cloudflare).
  3. Trust Signals:
    • SSL certificate (🔒 in browser).
    • Customer reviews (e.g., 4.8/5 on Daraz).
    • Secure payment badges (Visa/Mastercard logos).
  4. Accessibility: Screen-reader support (WCAG compliance).

Case Study: Himalayan Java’s Website

  • Problem: Slow load times in rural areas (UMTS networks).
  • Solution:
    • Edge caching (Cloudflare).
    • Compressed images (WebP format).
  • Result: 30% increase in orders from outside Kathmandu.

5. Evaluating E-Commerce Project Feasibility

Not all ideas work. Use this checklist before launching:

Feasibility Criteria

Funding Options for Graduates:

Option Pros Cons Nepal Example
Bootstrapping Full control Slow growth Early Himalayan Java (self-funded)
Angel Investors Fast cash, mentorship Equity loss Antariksh Jnawali (invested in Daraz)
Crowdfunding Validates demand Platform fees (e.g., Kickstarter) Nepali startups use Ketto
Bank Loans No equity loss Collateral required Nabil Bank’s SME loans for e-commerce

Worked Example: Launching a Nepali Grocery Delivery App

  1. Technical Feasibility:
    • Use Firebase (Google’s BaaS) for backend to avoid server costs.
    • Partner with local kirana stores for inventory.
  2. Financial Plan:
    • Seed funding: ₹500,000 from angel investors.
    • Break-even: 18 months (based on Pathao’s growth curve).
  3. Legal:
    • Register with DoICT for e-commerce license.
    • Comply with Nepali Consumer Protection Act.

In the Real World

  1. eSewa’s Payment Gateway

    • Technology Used: LTE/5G for mobile transactions, TLS 1.3 for encryption, HSMs for key storage.
    • Why It Works: Nepal’s 80% mobile penetration—eSewa processes ₹500M/month via mobile.
    • Security: 3D Secure for credit cards, biometric auth for fingerprint logins.
  2. Daraz’s Logistics Network

    • Wireless Tech: UMTS for GPS tracking, LTE for real-time delivery updates.
    • Infrastructure: AWS cloud for dynamic scaling during sales.
    • Challenge: Last-mile delivery in Nepal’s terrain → Daraz uses local hubs (not direct cloud routes).
  3. Nabil Bank’s Online Banking

    • Security Layers:
      • HSM for encryption keys.
      • WAF to block SQL injection.
      • MFA (OTP + biometrics).
    • Real-World Impact: 95% of transactions are fraud-free due to multi-layered security.

Exam Tip

This unit is conceptual + applied. Expect:

  1. Definitions + Comparisons:
    • "Differentiate UMTS and LTE" → Use the table above (speed, latency, use cases).
    • "Explain IDS vs. IPS" → Draw the Mermaid diagram showing how they work together.
  2. Scenario-Based Questions:
    • "How would you secure eSewa’s mobile app?" → Cover TLS 1.3, HSMs, MFA, and phishing training.
    • "Why did Daraz choose AWS?" → Mention scalability, cost, and global reach.
  3. Case Study Analysis:
    • "Analyze Pathao’s wireless tech" → Link LTE/5G latency to user satisfaction.
  4. Feasibility Plans:
    • "Propose an e-commerce startup" → Include tech stack, funding, and compliance.

Common Mistakes to Avoid:

  • Ignoring non-technical attacks (e.g., phishing)—20% of exam questions test this.
  • Assuming all e-commerce is cloud-based—some use on-premise (e.g., NTC).
  • Skipping real-world examples—always tie answers to Nepali companies (Daraz, eSewa, Nabil Bank).

Pro Tip:

  • Memorize the CIA Triad (Confidentiality, Integrity, Availability) and link it to every security question.
  • Practice drawing:
    • Wireless protocol stacks (OSI model).
    • Security layers (HSMs, WAFs, IDS/IPS).
    • User journeys (e-commerce site flow).

Hardware Security Module (HSM) device**Nabil Bank’s encryption key storage unit (Image: Alexander Klink, CC BY 3.0, via Wikimedia Commons)

Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 4.

Discussion

Loading…