E-commerceUnit 39 min read
E-Commerce Security Fundamentals: Threats, Cryptography & Safeguards
Unit 3 of E-commerce: Explores core security principles—cryptography, authentication, payment security, and threat mitigation—critical for protecting transactions, customer data, and business operations in digital marketplaces.
TAKEAWAYS:
- Learn how cryptography (symmetric/asymmetric) and hash functions encrypt data and verify integrity in e-commerce transactions.
- Understand common security threats (e.g., phishing, DDoS, man-in-the-middle) and how e-commerce platforms counter them.
- Compare client-server security (HTTPS, SSL/TLS) and data transaction security (PGP, digital signatures) with real-world examples.
- See how Nepal’s eSewa/Khalti and global platforms like PayPal use encryption to secure payments.
- Analyze SET Protocol and digital document security (e-signatures) with a worked example of a fraud-proof order confirmation.
- Master ubiquitous commerce properties (ubiquity, richness, information density) and their impact on security.
1. Introduction to E-Commerce Security
E-commerce security ensures confidentiality, integrity, and availability of data during online transactions. Without it, customers lose trust, businesses face fraud, and reputations suffer. Nepal’s Nepal Rastra Bank (NRB) mandates encryption for digital payments, while global giants like Google Pay use end-to-end encryption to protect user data.
Key Security Objectives in E-Commerce
flowchart TD
A["Confidentiality"] -->|"Prevent unauthorized access to data"| B["Encryption"]
C["Integrity"] -->|"Ensure data isn’t altered"| D["Hash Functions"]
E["Availability"] -->|"Prevent downtime or attacks"| F["DDoS Protection"]
G["Authentication"] -->|"Verify users/devices"| H["Biometrics + Tokens"]Why it matters:
- eSewa uses TLS 1.3 to encrypt transactions between users and banks.
- Daraz employs PCI-DSS compliance to secure credit card payments.
2. Cryptography in E-Commerce
Cryptography protects data by converting it into unreadable formats. E-commerce relies on two main types:
A. Symmetric Cryptography
- Uses the same key for encryption/decryption (fast but less secure for key exchange).
- Example: AES-256 (used by Ncell’s mobile banking app to encrypt user credentials).
flowchart TD A["Plaintext"] -->|"Encrypt with Key K"| B["Ciphertext"] B -->|"Decrypt with Key K"| A A B
B. Asymmetric Cryptography (Public-Key Cryptography)
- Uses two keys: public (shared) and private (secret).
- Example: SSL/TLS certificates (used by Khalti’s payment gateway to verify server identity).
flowchart TD A["Alice"] -->|"Public Key"| B["Bob"] B -->|"Encrypts Message"| C["Ciphertext"] C -->|"Decrypts with Private Key"| D["Alice"] A B C
Worked Example: If Pathao sends a rider’s location to a customer via encrypted API, AES-256 ensures only the intended recipient (customer’s app) can decrypt it.
3. Hash Functions and Digital Signatures
Hash functions convert data into fixed-size digest (one-way function). Used for:
- Data integrity (e.g., verifying a downloaded file hasn’t been tampered with).
- Digital signatures (proving a document’s authenticity).
How Hash Functions Work
flowchart TD
A["Original Data"] -->|"Hash Function (SHA-256)"| B["Fixed-Length Hash"]
B -->|"Compare with stored hash"| C["Verify Integrity"]Real-World Use:
- NEPSE uses SHA-256 to hash stock trade orders before processing.
- YouTube verifies video uploads using hash comparisons to detect duplicates.
4. Security Threats in E-Commerce
Even secure systems face risks. Common threats include:
| Threat | Description | Example in Nepal |
|---|---|---|
| Phishing | Fake emails/sites to steal credentials. | Fake "eSewa login" emails tricking users. |
| Man-in-the-Middle (MITM) | Intercepting unencrypted data. | Hackers stealing Khalti transaction details. |
| DDoS Attacks | Overloading servers to cause downtime. | Daraz Black Friday crashes due to traffic spikes. |
| Malware | Viruses/spyware infecting payment apps. | Ncell’s banking app infected via fake updates. |
| SQL Injection | Hacking databases by injecting malicious SQL. | Attack on a local e-commerce site’s user database. |
Mitigation Strategies:
- HTTPS (encryption for web traffic).
- Firewalls (blocking DDoS attacks).
- Multi-Factor Authentication (MFA) (e.g., Google Authenticator for eSewa).
5. Client-Server Security
E-commerce relies on secure communication between clients (users) and servers (businesses).
A. HTTPS and SSL/TLS
- HTTPS encrypts data between browser and server.
- SSL/TLS protocols ensure secure handshakes.
sequenceDiagram participant User participant Browser participant Server User->>Browser: Requests "https://khalti.com" Browser->>Server: TLS Handshake Browser->>Server: Encrypts Data Server-->>Browser: Decrypts Data Server-->>Browser: SSL Certificate (Verified)
Real Picture:
B. Secure Payment Gateways
- PCI-DSS Compliance: Mandatory for handling credit cards (e.g., PayPal, Stripe).
- Tokenization: Replaces card details with tokens (e.g., eSewa’s "Save Card" feature).
6. Data Transaction Security
Beyond client-server security, data in transit and at rest must be protected.
A. PGP (Pretty Good Privacy)
- Encrypts emails and files (used by Nepal’s legal e-filing systems).
- Combines symmetric encryption (for speed) + asymmetric encryption (for key exchange).
B. Digital Signatures
- Proves a document’s origin (e.g., NEPSE’s legally binding stock trade confirmations).
Worked Example: A Daraz order confirmation uses:
- SHA-256 hash of the order details.
- Digital signature from Daraz’s private key.
- Public key verification by the customer’s app to ensure authenticity.
7. Ubiquitous Commerce Properties & Security
E-commerce isn’t just online—it’s ubiquitous (anywhere, anytime). Key properties:
| Property | Description | Security Impact |
|---|---|---|
| Ubiquity | Accessible via any device (mobile, IoT). | Requires device authentication (e.g., Ncell’s SIM-based login). |
| Richness | High-quality media (video, AR). | Needs DRM (Digital Rights Management) to prevent piracy. |
| Information Density | Massive product/data availability. | Vulnerable to scraping attacks (e.g., Daraz’s product data theft). |
Example:
- Pathao’s app uses geofencing (ubiquity) but encrypts rider locations with AES-128 to prevent tracking.
8. SET Protocol and Digital Documents
The Secure Electronic Transaction (SET) Protocol ensures secure credit card payments.
How SET Works
sequenceDiagram
participant Customer
participant Merchant
participant Bank
Customer->>Bank: Sends encrypted card details (via SET)
Bank-->>Merchant: Verifies payment (without seeing card details)
Merchant-->>Customer: Confirms order (digitally signed)Real-World Use:
- Global banks (e.g., HSBC) use SET-like protocols for cross-border e-commerce.
- Nepal’s Ncell uses 3D Secure (a SET variant) for mobile payments.
In the Real World
eSewa’s Encrypted Transactions
- Idea: Uses TLS 1.3 + PCI-DSS to encrypt bank transfers.
- How: When you pay a merchant via eSewa, your card details never reach the merchant—only the bank verifies the payment.
Khalti’s Fraud Prevention
- Idea: Combines AI fraud detection (ubiquity) + hash-based order verification (integrity).
- How: If a transaction seems suspicious (e.g., high value from a new device), Khalti flags it for manual review.
Daraz’s Inventory Security
- Idea: Uses blockchain-like ledgers (information density) to track product authenticity.
- How: Each product has a unique QR code hash—scanning it verifies it’s not counterfeit.
Exam Tip
- Focus on contrasts: Compare symmetric vs. asymmetric encryption, SET vs. traditional payment gateways, and ubiquitous vs. traditional e-commerce.
- Apply to Nepal: Always relate threats (e.g., phishing in eSewa) or solutions (e.g., Ncell’s MFA) to local examples.
- Diagrams are key: Draw TLS handshake, SET protocol flow, or a threat comparison table—examiners love visuals!
- Worked examples: For hash functions, show how NEPSE verifies a stock trade. For ubiquity, explain Pathao’s device-based security.
- Security vs. usability trade-off: Discuss how stronger encryption (e.g., AES-256) slows down Khalti’s payment processing but reduces fraud.
Final Note: Security isn’t just theory—it’s what keeps Nepal’s digital economy running. Always think: "How would a hacker exploit this?" and "How does [local app] prevent it?"
Based on the TU BSc CSIT syllabus for E-commerce (CSC370), unit 3.
Discussion
Loading…