CSC370 E-commerce

E-commerceUnit 39 min read

E-Commerce Security Fundamentals: Threats, Cryptography & Safeguards

Unit 3 of E-commerce: Explores core security principles—cryptography, authentication, payment security, and threat mitigation—critical for protecting transactions, customer data, and business operations in digital marketplaces.

TAKEAWAYS:

  • Learn how cryptography (symmetric/asymmetric) and hash functions encrypt data and verify integrity in e-commerce transactions.
  • Understand common security threats (e.g., phishing, DDoS, man-in-the-middle) and how e-commerce platforms counter them.
  • Compare client-server security (HTTPS, SSL/TLS) and data transaction security (PGP, digital signatures) with real-world examples.
  • See how Nepal’s eSewa/Khalti and global platforms like PayPal use encryption to secure payments.
  • Analyze SET Protocol and digital document security (e-signatures) with a worked example of a fraud-proof order confirmation.
  • Master ubiquitous commerce properties (ubiquity, richness, information density) and their impact on security.

1. Introduction to E-Commerce Security

E-commerce security ensures confidentiality, integrity, and availability of data during online transactions. Without it, customers lose trust, businesses face fraud, and reputations suffer. Nepal’s Nepal Rastra Bank (NRB) mandates encryption for digital payments, while global giants like Google Pay use end-to-end encryption to protect user data.

Key Security Objectives in E-Commerce

flowchart TD
    A["Confidentiality"] -->|"Prevent unauthorized access to data"| B["Encryption"]
    C["Integrity"] -->|"Ensure data isn’t altered"| D["Hash Functions"]
    E["Availability"] -->|"Prevent downtime or attacks"| F["DDoS Protection"]
    G["Authentication"] -->|"Verify users/devices"| H["Biometrics + Tokens"]

Why it matters:

  • eSewa uses TLS 1.3 to encrypt transactions between users and banks.
  • Daraz employs PCI-DSS compliance to secure credit card payments.

2. Cryptography in E-Commerce

Cryptography protects data by converting it into unreadable formats. E-commerce relies on two main types:

A. Symmetric Cryptography

  • Uses the same key for encryption/decryption (fast but less secure for key exchange).
  • Example: AES-256 (used by Ncell’s mobile banking app to encrypt user credentials).
flowchart TD
  A["Plaintext"] -->|"Encrypt with Key K"| B["Ciphertext"]
  B -->|"Decrypt with Key K"| A
  A
  B

B. Asymmetric Cryptography (Public-Key Cryptography)

  • Uses two keys: public (shared) and private (secret).
  • Example: SSL/TLS certificates (used by Khalti’s payment gateway to verify server identity).
flowchart TD
  A["Alice"] -->|"Public Key"| B["Bob"]
  B -->|"Encrypts Message"| C["Ciphertext"]
  C -->|"Decrypts with Private Key"| D["Alice"]
  A
  B
  C

Worked Example: If Pathao sends a rider’s location to a customer via encrypted API, AES-256 ensures only the intended recipient (customer’s app) can decrypt it.


3. Hash Functions and Digital Signatures

Hash functions convert data into fixed-size digest (one-way function). Used for:

  • Data integrity (e.g., verifying a downloaded file hasn’t been tampered with).
  • Digital signatures (proving a document’s authenticity).

How Hash Functions Work

flowchart TD
    A["Original Data"] -->|"Hash Function (SHA-256)"| B["Fixed-Length Hash"]
    B -->|"Compare with stored hash"| C["Verify Integrity"]

Real-World Use:

  • NEPSE uses SHA-256 to hash stock trade orders before processing.
  • YouTube verifies video uploads using hash comparisons to detect duplicates.

4. Security Threats in E-Commerce

Even secure systems face risks. Common threats include:

Phishing (25%)Malware (20%)DDoS Attacks (15%)Data Breaches (20%)Man-in-the-Middle (20%)
Common e-commerce security threats by occurrence rate (approximate)
Threat Description Example in Nepal
Phishing Fake emails/sites to steal credentials. Fake "eSewa login" emails tricking users.
Man-in-the-Middle (MITM) Intercepting unencrypted data. Hackers stealing Khalti transaction details.
DDoS Attacks Overloading servers to cause downtime. Daraz Black Friday crashes due to traffic spikes.
Malware Viruses/spyware infecting payment apps. Ncell’s banking app infected via fake updates.
SQL Injection Hacking databases by injecting malicious SQL. Attack on a local e-commerce site’s user database.

Mitigation Strategies:

  • HTTPS (encryption for web traffic).
  • Firewalls (blocking DDoS attacks).
  • Multi-Factor Authentication (MFA) (e.g., Google Authenticator for eSewa).

5. Client-Server Security

E-commerce relies on secure communication between clients (users) and servers (businesses).

A. HTTPS and SSL/TLS

  • HTTPS encrypts data between browser and server.
  • SSL/TLS protocols ensure secure handshakes.
sequenceDiagram
  participant User
  participant Browser
  participant Server
  User->>Browser: Requests "https://khalti.com"
  Browser->>Server: TLS Handshake
  Browser->>Server: Encrypts Data
  Server-->>Browser: Decrypts Data
  Server-->>Browser: SSL Certificate (Verified)

Real Picture:

B. Secure Payment Gateways

  • PCI-DSS Compliance: Mandatory for handling credit cards (e.g., PayPal, Stripe).
  • Tokenization: Replaces card details with tokens (e.g., eSewa’s "Save Card" feature).

6. Data Transaction Security

Beyond client-server security, data in transit and at rest must be protected.

1995SSL 1.0 introduced(early encryption stan2006TLS 1.2standardized (current 2018TLS 1.3 released(modern security impro
Key milestones in SSL/TLS protocol evolution

A. PGP (Pretty Good Privacy)

  • Encrypts emails and files (used by Nepal’s legal e-filing systems).
  • Combines symmetric encryption (for speed) + asymmetric encryption (for key exchange).

B. Digital Signatures

  • Proves a document’s origin (e.g., NEPSE’s legally binding stock trade confirmations).

Worked Example: A Daraz order confirmation uses:

  1. SHA-256 hash of the order details.
  2. Digital signature from Daraz’s private key.
  3. Public key verification by the customer’s app to ensure authenticity.

7. Ubiquitous Commerce Properties & Security

E-commerce isn’t just online—it’s ubiquitous (anywhere, anytime). Key properties:

Property Description Security Impact
Ubiquity Accessible via any device (mobile, IoT). Requires device authentication (e.g., Ncell’s SIM-based login).
Richness High-quality media (video, AR). Needs DRM (Digital Rights Management) to prevent piracy.
Information Density Massive product/data availability. Vulnerable to scraping attacks (e.g., Daraz’s product data theft).

Example:

  • Pathao’s app uses geofencing (ubiquity) but encrypts rider locations with AES-128 to prevent tracking.

8. SET Protocol and Digital Documents

The Secure Electronic Transaction (SET) Protocol ensures secure credit card payments.

How SET Works

sequenceDiagram
    participant Customer
    participant Merchant
    participant Bank
    Customer->>Bank: Sends encrypted card details (via SET)
    Bank-->>Merchant: Verifies payment (without seeing card details)
    Merchant-->>Customer: Confirms order (digitally signed)

Real-World Use:

  • Global banks (e.g., HSBC) use SET-like protocols for cross-border e-commerce.
  • Nepal’s Ncell uses 3D Secure (a SET variant) for mobile payments.

In the Real World

  1. eSewa’s Encrypted Transactions

    • Idea: Uses TLS 1.3 + PCI-DSS to encrypt bank transfers.
    • How: When you pay a merchant via eSewa, your card details never reach the merchant—only the bank verifies the payment.
  2. Khalti’s Fraud Prevention

    • Idea: Combines AI fraud detection (ubiquity) + hash-based order verification (integrity).
    • How: If a transaction seems suspicious (e.g., high value from a new device), Khalti flags it for manual review.
  3. Daraz’s Inventory Security

    • Idea: Uses blockchain-like ledgers (information density) to track product authenticity.
    • How: Each product has a unique QR code hash—scanning it verifies it’s not counterfeit.

Exam Tip

  • Focus on contrasts: Compare symmetric vs. asymmetric encryption, SET vs. traditional payment gateways, and ubiquitous vs. traditional e-commerce.
  • Apply to Nepal: Always relate threats (e.g., phishing in eSewa) or solutions (e.g., Ncell’s MFA) to local examples.
  • Diagrams are key: Draw TLS handshake, SET protocol flow, or a threat comparison table—examiners love visuals!
  • Worked examples: For hash functions, show how NEPSE verifies a stock trade. For ubiquity, explain Pathao’s device-based security.
  • Security vs. usability trade-off: Discuss how stronger encryption (e.g., AES-256) slows down Khalti’s payment processing but reduces fraud.

Final Note: Security isn’t just theory—it’s what keeps Nepal’s digital economy running. Always think: "How would a hacker exploit this?" and "How does [local app] prevent it?"

Based on the TU BSc CSIT syllabus for E-commerce (CSC370), unit 3.

Discussion

Loading…