Cyber Law And Professional EthicsUnit 411 min read
Intellectual Property Rights & Digital Security
Unit 4 of Cyber Law And Professional Ethics explores how to legally protect creative and digital assets (IPR), the risks of unauthorized use, and security measures like digital signatures and the CIA triad to safeguard data—with real-world examples from Nepal and globally.
TAKEAWAYS:
- Intellectual property (IP) includes patents, copyrights, trademarks, and trade secrets, all legally protected to incentivize innovation.
- Plagiarism and piracy are IP violations; cyber-squatting (registering a domain to exploit a brand) is a growing digital threat.
- Copyright protects original works (code, music, books) for 70 years post-author; fair use allows limited reuse (e.g., reviews).
- Digital signatures use asymmetric encryption (public/private keys) to verify identity and authenticity in contracts and transactions.
- The CIA triad (Confidentiality, Integrity, Availability) is the foundation of cybersecurity; breaches can cripple businesses (e.g., NTC data leaks).
- Nepal’s Cyber Security Act (2075) and WIPO treaties enforce IPR; global platforms like Daraz and eSewa rely on IP protection for trust.
1. Intellectual Property (IP) and Its Types
Intellectual property (IP) refers to creations of the mind—such as inventions, literary works, designs, symbols, names, and images used in commerce—that are legally protected. Unlike physical property, IP is intangible but can be monetized, licensed, or enforced.
Types of Intellectual Property
Why Protect IP?
- Incentivizes innovation: Creators earn revenue from their work (e.g., a Nepali app developer monetizing a Pathao-like app).
- Prevents exploitation: Without IP, competitors could copy ideas without compensation.
- Economic growth: Strong IP laws attract investment (e.g., NEPSE-listed tech startups).
2. Plagiarism and Its Types
Plagiarism is the unauthorized use of someone else’s work without credit, a major IP violation in academia and industry.
Types of Plagiarism
| Type | Description | Example |
|---|---|---|
| Direct Plagiarism | Copying text verbatim without citation. | Copy-pasting a Wikipedia article into an assignment. |
| Partial Plagiarism | Borrowing sections without attribution. | Using 3 sentences from a research paper without quotes. |
| Self-Plagiarism | Reusing one’s own work without permission. | Submitting the same thesis chapter in two different courses. |
| Mosaic Plagiarism | Patchworking ideas from multiple sources without proper citation. | Mixing quotes from 5 books into an essay without referencing. |
| Accidental Plagiarism | Unintentional reuse due to poor citation practices. | Forgetting to cite a source in a report. |
(Image shows a Turnitin report highlighting matched text in red.)
Consequences of Plagiarism
- Academic: Failure, expulsion (e.g., TU revoking degrees for plagiarized theses).
- Professional: Lawsuits, fines (e.g., a Nepali software firm sued for copying a foreign UI design).
- Reputational: Damage to personal/brand trust (e.g., a YouTuber’s channel banned for stolen content).
3. Protecting IP: Copyright and Beyond
Copyright automatically protects original works (e.g., code, music, books) upon creation, but registration strengthens legal claims.
How Copyright Works
- Eligibility: Original works fixed in a tangible form (e.g., a Python script, a song recording).
- Duration: Life of the author + 70 years (Nepal follows WIPO conventions).
- Rights: Control over reproduction, distribution, adaptation (e.g., a Nepali band licensing its music to eSewa ads).
(Image shows the WIPO logo alongside a timeline: "70 years post-author death.")
Fair Use vs. Copyright Infringement
| Fair Use | Copyright Infringement |
|---|---|
| Allows limited use for criticism, education, or parody. | Unauthorized copying or distribution. |
| Example: Quoting a song in a YouTube review. | Example: Streaming pirated movies on a local server. |
| Must transform the original work. | No permission or license obtained. |
Worked Example: Daraz’s Copyright Policy Daraz protects its product images and descriptions via copyright. If a seller copies a competitor’s listing without permission, Daraz can:
- Remove the listing.
- Issue a DMCA takedown notice (Digital Millennium Copyright Act).
- Sue for damages (e.g., ₹50,000–₹500,000 in Nepal under the Cyber Security Act).
4. Digital Signatures and Authentication
Digital signatures verify the identity and integrity of digital documents using asymmetric encryption.
How Digital Signatures Work
- Private Key: The sender signs the document (e.g., a contract) with their private key.
- Public Key: The recipient verifies the signature using the sender’s public key (published on a certificate).
- Hash Function: A unique fingerprint of the document ensures tamper-proofing.
Mermaid Diagram: Digital Signature Process
sequenceDiagram
participant Sender
participant PrivateKey
participant Document
participant HashFunction
participant PublicKey
participant Recipient
Sender->>PrivateKey: Signs document (private key)
Document->>HashFunction: Creates hash
HashFunction->>PrivateKey: Encrypts hash
Sender->>Recipient: Sends document + signature
Recipient->>PublicKey: Decrypts hash with sender’s public key
Recipient->>HashFunction: Recreates hash from document
Recipient->>PublicKey: Compares hashes (verifies authenticity)Real-World Use: eSewa Transactions
- When you pay via eSewa, the transaction is digitally signed to:
- Prove you authorized the payment.
- Prevent fraud (e.g., a hacker altering the amount).
- The signature uses Nepal Rastra Bank’s public key for verification.
5. The CIA Triad: Confidentiality, Integrity, Availability
The CIA triad is the core of cybersecurity, ensuring data is:
- Confidential: Accessed only by authorized users (e.g., NTC’s customer data).
- Integral: Unchanged and accurate (e.g., bank transaction records).
- Available: Accessible when needed (e.g., Ncell’s network uptime).
Implementing CIA at Different Levels
| Level | Confidentiality | Integrity | Availability |
|---|---|---|---|
| Organizational | Role-based access (RBAC), encryption (e.g., NEPSE’s data encryption). | Checksums, hashing (e.g., audit logs for stock trades). | Redundant servers, backup generators. |
| Network | Firewalls (e.g., NTC’s VPN for employees). | Firewall rules, IDS/IPS (e.g., blocking SQL injection). | Load balancers, failover systems. |
| End User | Strong passwords, MFA (e.g., Ncell’s SMS OTP). | Antivirus software (e.g., blocking ransomware). | Regular software updates. |
CIA Breach Example: NTC Data Leak (2022)
- Issue: NTC’s customer database was exposed due to weak encryption (confidentiality breach).
- Impact:
- Integrity: Fake calls impersonating NTC staff.
- Availability: Overloaded customer service lines.
- Fix: NTC implemented:
- Confidentiality: Tokenization of PII (Personally Identifiable Information).
- Integrity: Blockchain for transaction logs.
- Availability: Cloud-based failover systems.
6. Digital Security Threats and Countermeasures
| Threat | Description | Countermeasure |
|---|---|---|
| Phishing | Fake emails/tricks to steal credentials (e.g., "Reset your eSewa password"). | Phishing awareness training, DMARC for emails. |
| Malware | Viruses, ransomware (e.g., locking Daraz’s inventory data). | Antivirus, regular patches. |
| Man-in-the-Middle (MitM) | Intercepting data (e.g., hacking a Pathao rider’s payment). | HTTPS, VPNs, TLS encryption. |
| Cybersquatting | Registering domains like "daraz.com.ngo" to exploit Daraz’s brand. | Trademark registration, ICANN dispute resolution. |
| Insider Threats | Employees leaking data (e.g., a bank teller selling customer records). | Access logs, mandatory vacations for sensitive roles. |
(Image shows an email with "Urgent: Verify Account" and a suspicious link.)
In the Real World
eSewa’s Digital Signatures
- Idea: Uses digital signatures to authenticate transactions, preventing fraud in peer-to-peer payments.
- How: Every transfer is signed with eSewa’s private key and verified with the sender’s public key, tied to their mobile number.
Daraz’s Copyright Protection
- Idea: Copyrights its product images and descriptions to prevent sellers from copying listings.
- How: Automated tools scan for duplicate content; violators face takedowns or legal action under Nepal’s Cyber Security Act.
NEPSE’s CIA Implementation
- Idea: Protects stock market data with the CIA triad.
- How:
- Confidentiality: Only brokers with licenses access trade data.
- Integrity: Every trade is logged with a timestamp and hash.
- Availability: Multiple data centers ensure 24/7 access.
Exam Tip
- Focus on definitions: Always start answers with clear definitions (e.g., "Intellectual property is...").
- Link theory to Nepal: Use local examples (eSewa, Daraz, NTC) to show real-world application.
- CIA triad is high-scoring: Explain how to implement it at three levels (organizational, network, end user) with examples.
- Plagiarism types: Memorize the 5 types and their examples for short-answer questions.
- Digital signatures: Draw the process (use the Mermaid diagram above) to explain how hashing + encryption work.
- Past paper patterns:
- 20 marks: Define IP + explain copyright/trademark protection (e.g., "How does Daraz protect its brand?").
- 15 marks: CIA triad implementation (compare organizational vs. network levels).
- 10 marks: Short-answer on threats (e.g., "What is cybersquatting? Give an example.").
Key Formula for Full Marks:
- Define the concept (1 mark).
- Explain with real examples (3–5 marks).
- Compare (if applicable, e.g., CIA at different levels) (2–3 marks).
- Link to Nepal/global laws (1–2 marks).
- Visual aid: Include a diagram/table where possible (bonus marks).
Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 4.
Discussion
Loading…