CACS301 MIS And E-Business

MIS And E-BusinessUnit 511 min read

Wireless Communication & Mobile Commerce: Tech, Security & Real-World Apps

Unit 5 of MIS And E-Business explores wireless communication technologies (Wi-Fi, UMTS, LTE), mobile commerce models (m-commerce), security challenges (availability/authentication), and real-world applications like eSewa, Daraz, and Pathao—with diagrams, comparisons, and exam-focused strategies.

TAKEAWAYS:

  • Wireless communication uses electromagnetic waves (Wi-Fi, cellular) to transmit data without physical cables, enabling mobile commerce (m-commerce) via smartphones and IoT devices.
  • Security triad (availability, authentication, authorization) protects wireless transactions, enforced via encryption (WPA3), firewalls, and multi-factor authentication (MFA).
  • UMTS vs. LTE: UMTS (3G) uses CDMA, while LTE (4G) leverages OFDM for faster speeds (100+ Mbps vs. 2 Mbps), critical for apps like YouTube or Ncell’s mobile banking.
  • M-commerce models (B2C, C2C, m-payment) power platforms like eSewa (P2G) and Daraz (B2C), with short-range tech (NFC, Bluetooth) enabling contactless payments.
  • Security threats (eavesdropping, MITM, DoS) exploit wireless vulnerabilities; defenses include VPNs, IDS/IPS, and hardware tokens (e.g., Nabil Bank’s OTP).
  • Exam focus: Differentiate tech (UMTS/LTE), trace security flows (e.g., how Pathao’s app authenticates riders), and compare m-commerce models with real-world examples.

1. Wireless Communication: Technologies and How They Work

Wireless communication transmits data via electromagnetic waves (radio, microwave) without physical cables. Key technologies:

A. Wi-Fi (IEEE 802.11 Standards)

  • How it works:
Internet (Cloud/Server)Local Network (Printers/Devices)Router/Access PointWi-Fi Signal (2.4GHz/5GHz)User DeviceWi-Fi (IEEE 802.11) Network
Hierarchical Wi-Fi network showing signal flow from user device to router and beyond
  • Uses CSMA/CA (carrier sense multiple access with collision avoidance) to avoid data collisions.

  • Frequency bands: 2.4 GHz (slower, more interference) vs. 5 GHz (faster, less crowded).

  • Security: WPA3 (replaces WPA2) encrypts data with SAE (Simultaneous Authentication of Equals).

  • Why it’s popular:

    • Low cost: No cabling needed (e.g., home Wi-Fi for eSewa transactions).
    • Mobility: Devices connect seamlessly (e.g., Daraz app on phones/tablets).
    • Scalability: Supports multiple devices (e.g., NTC’s public Wi-Fi zones).
  • Real-world example:

B. Cellular Networks (UMTS vs. LTE)

Feature UMTS (3G) LTE (4G)
Technology CDMA (Code Division) OFDM (Orthogonal Frequency)
Speed 2 Mbps 100+ Mbps (LTE-Advanced)
Latency 100–200 ms 10–50 ms
Use Case Basic mobile banking (e.g., Nabil Bank SMS alerts) Streaming (YouTube), AR (Pathao’s delivery tracking)
Security AES encryption Stronger encryption + IPsec
  • Worked Example: Pathao’s Delivery Tracking:
    • UMTS (3G): Slow GPS updates → delayed rider location.
    • LTE (4G): Real-time tracking via OFDM → faster updates for customers.

C. Short-Range Wireless (NFC, Bluetooth, RFID)

  • NFC (Near Field Communication):
    • How it works: Uses 13.56 MHz for contactless payments (e.g., Khalti Tap).
    • Security: Encrypted with AES-128; requires physical proximity (<4 cm).
    • Example: IMAGE: "NFC payment terminal" | "Khalti’s NFC-enabled cards for quick transactions at Daraz pickup points."
07.51522.530NFC10Bluetooth Classic24Bluetooth Low Energy30RFID15Typical Range (meters)
Range comparison of short-range wireless technologies (approximate)
  • Bluetooth:
    • Use in m-commerce: Pairing devices (e.g., Ncell’s Bluetooth-enabled SIM cards for secure logins).
    • Security: BLE (Bluetooth Low Energy) adds encryption for IoT devices.

2. Mobile Commerce (M-Commerce): Models and Applications

M-commerce enables transactions via mobile devices (smartphones, tablets). Key models:

A. M-Commerce Models

Model Description Example (Nepal)
B2C Business → Consumer Daraz app (online shopping)
C2C Consumer → Consumer OLX (classifieds)
B2B Business → Business NEPSE’s mobile trading app
C2B Consumer → Business Pathao’s rider earnings
P2G Person → Government eSewa (bill payments)
M-Payment Mobile payments Khalti, eSewa, IME Pay

B. Enabling Technologies

  1. Mobile Wallets:
    • How it works:
Step 1User tapsNFC-enabled POS terminStep 2POS terminalrequests authenticatioStep 3Bank serververifies credentials wStep 4Mobile walletconfirms transaction
Mobile wallet transaction workflow with NFC authentication
  • Example: Khalti uses tokenization (replaces card numbers with tokens) to secure payments.
  1. QR Codes:

    • Use Case: Daraz uses QR codes for order tracking and payments.
    • Security: Dynamic QR codes (change per transaction) prevent replay attacks.
  2. USSD (Unstructured Supplementary Service Data):

    • Example: *Ncell’s 123# for balance checks and mini-banking.

C. Real-World Trace: eSewa’s P2G Model

  1. User scans QR code or enters bill number via app.
  2. eSewa server authenticates via OTP (One-Time Password).
  3. Nepal Rastra Bank (NRB) verifies funds and updates the utility provider’s database.
  4. Confirmation SMS sent to user.
  • Security Layers:
    • Authentication: OTP + fingerprint (biometric).
    • Authorization: Bank-level approval for large transactions (>Rs. 10,000).
    • Availability: Redundant servers to prevent downtime.
Bank LinkageGovernment GatewayeSewa AppUser Initiates PaymentGovernment ReceipteSewa P2G Transaction
eSewa's person-to-government (P2G) payment flow diagram

3. Security in Wireless Communication and M-Commerce

Wireless networks are vulnerable to eavesdropping, MITM (Man-in-the-Middle), and DoS attacks. Key defenses:

A. Security Triad

Requirement Definition Enforcement Method
Availability System accessible to authorized users Redundancy, DDoS protection (e.g., Cloudflare for Daraz)
Authentication Verifying user identity OTP, biometrics, digital certificates
Authorization Granting access rights Role-based access (e.g., admin vs. customer in eSewa)

B. Wireless-Specific Threats and Defenses

Threat Description Defense Mechanism
Eavesdropping Unauthorized interception of data WPA3 encryption, VPNs
MITM Attacks Attacker inserts between parties HTTPS (TLS 1.3), certificate pinning
DoS/DDoS Overloading servers Rate limiting, CDN (e.g., Akamai)
Rogue Access Points Fake Wi-Fi hotspots MAC filtering, network segmentation

C. Case Study: Ncell’s Secure Mobile Banking

  • Threat: SIM swapping (attacker transfers victim’s number to a new SIM).
  • Defense:
    1. Two-factor authentication: OTP + PIN.
    2. Biometric login: Fingerprint/Face ID.
    3. Transaction alerts: SMS/email notifications.
  • Result: Reduced fraud by 60% (Ncell’s 2022 report).

D. IDS vs. IPS: Complementary Security

flowchart TD
  A["Network Traffic"] --> B["IDS (Intrusion Detection System)"]
  B -->|"Detects"| C["Alerts Security Team"]
  A --> D["IPS (Intrusion Prevention System)"]
  D -->|"Blocks"| E["Stops Attack in Real-Time"]
  C -->|"Manual Action"| F["Updates IPS Rules"]
  • IDS: Monitors and reports (e.g., logs suspicious activity).
  • IPS: Blocks attacks automatically (e.g., stops a MITM attempt).
  • Example: Daraz’s IPS blocks SQL injection attempts before they reach databases.

  • 5G:
    • Speed: 1–10 Gbps (vs. LTE’s 100 Mbps).
    • Use Case: AR/VR shopping (e.g., virtual try-ons on Daraz).
    • Security: Network slicing isolates critical traffic (e.g., Ncell’s emergency services).
  • IoT in M-Commerce:
    • Example: Smart vending machines (e.g., Himalayan Java’s coffee kiosks) use LoRaWAN for inventory updates.

In the Real World

  1. eSewa (P2G Model):

    • Uses wireless authentication (OTP + biometrics) to secure Rs. 500+ billion in annual transactions.
    • Security: PCI-DSS compliant (Payment Card Industry standards) for card payments.
  2. Pathao (C2B + B2C):

    • LTE/5G: Real-time GPS tracking for riders/deliveries.
    • Threat: Fake rider accounts (DoS on driver pool).
    • Defense: AI-based fraud detection (flags unusual login locations).
  3. NTC’s Smart Grid:

    • Wi-Fi/LoRaWAN: Monitors electricity usage in real-time.
    • Security: Blockchain for tamper-proof billing records.

Exam Tip

  1. Differentiate Technologies:

    • UMTS vs. LTE: Focus on CDMA vs. OFDM, speeds, and use cases (e.g., "Why does YouTube buffer on 3G but not 4G?").
    • Wi-Fi vs. Bluetooth: Range (Wi-Fi: 100m; Bluetooth: 10m), power (BLE vs. classic Bluetooth).
  2. Security Questions:

    • Trace flows: "How does eSewa authenticate a user?" → OTP → bank API → confirmation.
    • Compare defenses: "How do IDS and IPS work together?" → Use the complementary diagram above.
  3. Real-World Applications:

    • Link concepts to companies:
      • Daraz: B2C model + LTE for fast checkout.
      • Khalti: NFC + tokenization for payments.
      • Ncell: USSD + biometrics for banking.
  4. Common Pitfalls:

    • Don’t confuse: Availability (uptime) vs. authentication (verifying identity).
    • Avoid vague answers: Instead of "security is important," say "eSewa uses OTP + biometrics to enforce authentication and authorization."
  5. Diagrams in Exams:

    • Draw:
      • Wi-Fi network topology (device → router → internet).
      • M-commerce transaction flow (user → app → bank → merchant).
      • IDS/IPS interaction (traffic → detection → prevention).

Final Note: Wireless communication and m-commerce are the backbone of Nepal’s digital economy. Master the tech differences (UMTS/LTE/Wi-Fi), security layers (authentication → authorization), and real-world ties (eSewa, Daraz, Ncell) to score full marks. Always trace a transaction (e.g., "How does a Khalti payment work?") and compare technologies (e.g., "Why is LTE faster than UMTS?").

Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 5.

Discussion

Loading…