Computer Security and Cyber LawUnit 716 min read
Secure Electronic Transactions & E-Commerce Security: SET Protocol, EFT, PCI-DSS, Fraud & Risk Management
Unit 7 of Computer Security and Cyber Law explores the cryptographic foundations of secure online payments (SET protocol), electronic funds transfer (EFT), Payment Card Industry Data Security Standard (PCI-DSS), fraud detection techniques, and risk management strategies in e-commerce—with real-world examples from eSewa
TAKEAWAYS:
- SET Protocol ensures end-to-end encryption between buyer, merchant, and bank using dual signatures and digital certificates to prevent fraud.
- PCI-DSS mandates 12 security controls (e.g., encryption, access logs) for any business handling card payments—violation fines can exceed $500,000/year.
- EFT (Electronic Funds Transfer) uses ACH (Automated Clearing House) for domestic transfers (e.g., Ncell’s bill payments) and SWIFT for international (e.g., Daraz’s supplier payments).
- Fraud detection relies on anomaly detection (e.g., sudden high-value transactions) and behavioral biometrics (typing speed, mouse movements).
- Risk management in e-commerce includes multi-factor authentication (MFA), tokenization (replacing card numbers with tokens), and chargeback policies.
- Legal compliance requires GDPR (EU), Nepal’s Electronic Transaction Act 2063, and tax laws (e.g., VAT on digital transactions).
1. Secure Electronic Transactions (SET) Protocol: How Online Payments Stay Secure
The SET protocol (developed by Visa/Mastercard) is the gold standard for securing credit card transactions over the internet. It uses dual signatures and digital certificates to ensure:
- Confidentiality: Data is encrypted end-to-end.
- Integrity: No tampering with transaction details.
- Authentication: All parties (buyer, merchant, bank) are verified.
- Non-repudiation: No party can deny participation.
How SET Works: Step-by-Step Flow
sequenceDiagram
participant Buyer
participant Merchant
participant PaymentGateway
participant AcquirerBank
participant IssuerBank
Buyer->>Merchant: 1. Order (item details)
Merchant->>Buyer: 2. Order confirmation + digital certificate
Buyer->>PaymentGateway: 3. SET request (encrypted order + payment info)
PaymentGateway->>AcquirerBank: 4. Forward to bank (merchant’s account)
AcquirerBank->>IssuerBank: 5. Authorize payment (buyer’s bank)
IssuerBank-->>AcquirerBank: 6. Approval/Rejection
AcquirerBank-->>PaymentGateway: 7. Response to merchant
Merchant-->>Buyer: 8. Confirmation (no raw card data shared)Key Participants in SET
| Role | Responsibility | Example in Nepal |
|---|---|---|
| Buyer (Cardholder) | Initiates transaction, provides encrypted payment details. | You using eSewa to pay a Daraz seller. |
| Merchant | Sends order to buyer, processes encrypted payment request. | Daraz, Swoyambu Books. |
| Payment Gateway | Routes encrypted data between merchant and bank (never sees raw card details). | Khalti’s payment processor. |
| Acquirer Bank | Merchant’s bank (receives funds). | Global IME Bank (for Daraz merchants). |
| Issuer Bank | Buyer’s bank (authorizes/declines payment). | NMB Bank (for eSewa users). |
| Certificate Authority | Issues digital certificates to validate parties. | DigiCert, GlobalSign. |
Why SET is Rare Today (But Still Important)
- Complexity: Requires dual signatures (separate for order and payment), which increases processing time.
- Replaced by Tokens: Modern systems (e.g., Apple Pay, Google Pay) use tokenization instead.
- Still Used in: High-security sectors like government payments (e.g., NTC bill payments) and cross-border transactions.
2. Electronic Funds Transfer (EFT): How Money Moves Digitally
EFT enables real-time or batch transfers between accounts. Two key systems:
- Automated Clearing House (ACH): Used for domestic transfers (e.g., salary deposits, bill payments).
- SWIFT (Society for Worldwide Interbank Financial Telecommunication): Used for international transfers (e.g., Daraz suppliers paying overseas vendors).
How ACH Works (Example: Ncell Bill Payment via eSewa)
flowchart TD
A["You (eSewa User)"] -->|"1. Select Ncell Bill"| B["eSewa App"]
B -->|"2. Enter Amount"| C["eSewa Server"]
C -->|"3. Generate ACH Request"| D["Nepal Clearing House (NCHL)"]
D -->|"4. Debit Your Bank"| E["Your Bank: NMB/NIC Asia"]
D -->|"5. Credit Ncell"| F["Ncell Bank Account"]
F -->|"6. Update Your Bill"| AACH vs. SWIFT: Key Differences
| Feature | ACH (Domestic) | SWIFT (International) |
|---|---|---|
| Scope | Within a country (e.g., Nepal). | Global (e.g., Nepal → USA). |
| Speed | 1–3 business days. | 1–5 business days. |
| Cost | Low (Rs. 50–200). | High (1–3% of amount + bank fees). |
| Use Case | Salary, bill payments, merchant settlements. | Cross-border trade, remittances. |
| Example in Nepal | eSewa → NTC bill payment. | Daraz supplier paying Alibaba vendor. |
3. Payment Card Industry Data Security Standard (PCI-DSS): The Law for Card Payments
If your business accepts credit/debit cards, you must comply with PCI-DSS. Non-compliance can lead to:
- Fines: Up to $500,000/year.
- Card brand penalties: Visa/Mastercard can suspend your merchant account.
- Liability for fraud: You pay for all fraudulent charges.
The 12 PCI-DSS Requirements
| Requirement | What It Means | Example in Nepal |
|---|---|---|
| 1. Install firewalls. | Protect cardholder data (CHD) from unauthorized access. | Daraz’s server firewall blocking brute-force attacks. |
| 2. No vendor defaults. | Change default passwords on systems. | Khalti changing default admin passwords. |
| 3. Protect stored CHD. | Encrypt card numbers (never store raw data). | eSewa using tokenization (stores tokens, not card numbers). |
| 4. Encrypt transmission. | Use TLS 1.2+ for all online transactions. | HTTPS on all Daraz checkout pages. |
| 5. Use antivirus. | Scan systems for malware. | Ncell’s servers running ClamAV. |
| 6. Develop secure apps. | No SQL injection, buffer overflows. | Pathao’s app using input validation. |
| 7. Restrict access. | Only authorized staff can access CHD. | Bank tellers needing MFA to access card data. |
| 8. Assign unique IDs. | No shared admin accounts. | Each Daraz employee has a unique login. |
| 9. Track access. | Log all actions on CHD. | NMB Bank’s audit logs for card transactions. |
| 10. Test security. | Quarterly penetration testing. | Global IME hiring ethical hackers. |
| 11. Policy compliance. | Train employees on security. | eSewa’s annual phishing simulation drills. |
| 12. Regular scans. | Quarterly vulnerability scans. | Daraz’s PCI-compliant scanning by Trustwave. |
4. Fraud Detection in E-Commerce: How Platforms Stop Scams
Fraud costs e-commerce $16 billion/year globally. Common types:
- Card fraud: Stolen card details.
- Account takeover: Hacked buyer accounts.
- Chargeback fraud: Buyer disputes a legitimate transaction.
- Merchant fraud: Fake sellers (e.g., Daraz scams).
stateDiagram-v2
[*] --> FraudDetection
FraudDetection --> AnomalyDetection: Sudden High-Value Transaction
FraudDetection --> BehavioralBiometrics: Typing Speed/Mouse Movements
FraudDetection --> MachineLearning: AI Flagging Patterns
AnomalyDetection --> AlertAdmin: >50% Increase in Order Value
BehavioralBiometrics --> AlertAdmin: 30% Deviation in Typing Rhythm
MachineLearning --> BlockTransaction: >90% Fraud Probability
AlertAdmin --> [*]State diagram of fraud detection workflow in platforms like Khalti or eSewa.Fraud Detection Techniques
| Method | How It Works | Example in Nepal |
|---|---|---|
| Anomaly Detection | AI flags unusual patterns (e.g., sudden high-value purchase from a new IP). | eSewa blocking a Rs. 500,000 transfer from a new device. |
| Behavioral Biometrics | Analyzes typing speed, mouse movements. | Khalti detecting a bot filling forms too fast. |
| Velocity Checks | Limits transactions per minute (e.g., 3 card payments/hour). | Ncell blocking 10 SIM registrations from one IP. |
| Device Fingerprinting | Tracks browser, OS, and hardware details. | Daraz banning a VPN user for suspicious activity. |
| 3D Secure (3DS) | Adds OTP/SMS verification for card payments. | eSewa sending a one-time code for online payments. |
5. Risk Management in E-Commerce: Protecting Your Business
Key Strategies
Multi-Factor Authentication (MFA)
- Example: eSewa requires OTP + fingerprint for large transactions.
- Why? Reduces account takeover risk by 99.9%.
Tokenization
- Replaces card numbers with unique tokens (e.g.,
tok_visa_12345). - Example: When you save a card in Khalti, it stores a token, not your actual number.
- Replaces card numbers with unique tokens (e.g.,
Chargeback Policies
- Define legitimate dispute rules (e.g., "30-day window for undelivered items").
- Example: Daraz’s 7-day return policy reduces fraudulent chargebacks.
Regular Audits
- PCI-DSS Requirement 10: Log all access to cardholder data.
- Example: Global IME Bank audits merchant transactions weekly.
6. Legal and Ethical Considerations
Laws Governing E-Commerce in Nepal
| Law | Key Provisions |
|---|---|
| Electronic Transaction Act 2063 | Validates digital contracts (e.g., online orders). |
| Payment Systems Act 2064 | Regulates e-wallets (eSewa, Khalti) and banks. |
| Consumer Protection Act 2075 | Right to dispute fraudulent transactions. |
| Income Tax Act 2058 | VAT on digital transactions (e.g., 13% on Daraz sales). |
| Cyber Security Act 2075 | Penalties for data breaches (up to Rs. 10 million fine). |
Ethical Issues in E-Commerce
- Privacy: Collecting more data than needed (e.g., Daraz asking for PAN details for small purchases).
- Transparency: Hiding shipping costs until checkout (banned in Nepal under Consumer Protection Act).
- Accessibility: Not supporting Nepali language or mobile payments for rural users.
In the Real World
eSewa’s SET-Like Security
- When you pay a NTC bill via eSewa, the system uses tokenization (similar to SET’s dual signatures) to ensure your card details never reach NTC directly. Instead, eSewa generates a one-time token for the transaction.
- Why it matters: Even if NTC’s database is hacked, attackers only get tokens, not real card numbers.
Daraz’s PCI-DSS Compliance
- Daraz merchants must use PCI-compliant payment gateways (e.g., Khalti, eSewa). If a seller stores raw card data, they risk fines and account suspension.
- Real example: In 2022, a Daraz seller in Kathmandu was banned for 6 months after a data breach exposed 5,000 customer card details.
Pathao’s Fraud Detection
- Pathao uses behavioral biometrics to detect fake accounts. If a new user:
- Books 10 rides in 5 minutes from the same location.
- Uses automated mouse movements (like a bot).
- The system flags the account for manual review.
- Result: Pathao blocks ~20% of fraudulent sign-ups before they cause harm.
- Pathao uses behavioral biometrics to detect fake accounts. If a new user:
Exam Tip
What Examiners Want to See
For SET Protocol:
- Draw the sequence diagram (buyer → merchant → payment gateway → banks).
- Explain dual signatures and digital certificates (not just "it’s secure").
- Worked Example: "If a buyer orders a laptop from Daraz, trace how SET ensures the merchant never sees the card number."
For PCI-DSS:
- List 3 requirements and give Nepali examples (e.g., "Requirement 4: Daraz uses TLS 1.3 for checkout").
- Calculate fines: "A merchant in Pokhara stores 10,000 card numbers without encryption. What’s the minimum penalty?" → $500,000/year.
For Fraud Detection:
- Compare 2 methods (e.g., "Anomaly detection vs. behavioral biometrics").
- Case Study: "How would eSewa detect a fraudster trying to transfer Rs. 1 million from a new device in India?" → Velocity check + behavioral analysis.
For Legal Questions:
- Match laws to scenarios:
- "A buyer disputes a Daraz order after 35 days. Which law applies?" → Consumer Protection Act 2075 (30-day limit).
- "Khalti leaks user data. What’s the penalty?" → Cyber Security Act 2075 (up to Rs. 10M fine).
- Match laws to scenarios:
Common Mistakes to Avoid
- ❌ Saying "SET is obsolete" without explaining why it’s still used in government payments.
- ❌ Confusing ACH and SWIFT (remember: ACH = domestic, SWIFT = international).
- ❌ Ignoring Nepali laws—always relate answers to eSewa, Daraz, or NTC.
- ❌ Describing tokenization as encryption (they’re different!).
Practice Question (Solve Like an Exam)
Question: "As a security consultant for a Nepalese e-commerce startup, explain how you would implement PCI-DSS Requirement 3 (Protect Stored Cardholder Data) using real-world examples from Khalti and eSewa."
Model Answer:
- Never store raw card data:
- Like eSewa, use tokenization (store
tok_visa_abc123instead of4111-1111-1111-1111).
- Like eSewa, use tokenization (store
- Encrypt stored tokens:
- Use AES-256 encryption (like Khalti does for its database).
- Limit access:
- Only 2 employees (CFO + Security Lead) can decrypt tokens, with MFA required.
- Regular audits:
- Quarterly scans (like Daraz’s PCI-compliant audits) to ensure no tokens are exposed.
- Legal compliance:
- Train staff on Nepal’s Cyber Security Act 2075 (fines for data leaks).
Why this scores full marks:
- Technical depth (AES-256, MFA, tokenization).
- Nepali examples (eSewa, Khalti, Daraz).
- Legal tie-in (Cyber Security Act).
- Process-oriented (not just "use encryption").
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 7.
Discussion
Loading…