Essential of e-BusinessUnit 510 min read
Electronic Payment Systems & Security: Types, Workflows & Safeguards
Unit 5 of Essential of e-Business explores the core of digital transactions—how electronic payment systems (EPS) function, their security risks, and best practices to protect sensitive data. This note covers EPS types (cards, wallets, bank transfers), security protocols (encryption, tokens, fraud detection), and real-w
TAKEAWAYS:
- Electronic payment systems (EPS) replace cash with digital transactions, reducing fraud but introducing new security risks like phishing and data breaches.
- Types of EPS: Card-based (debit/credit), digital wallets (eSewa, Khalti), bank transfers (RTGS, NEFT), and cryptocurrencies (Bitcoin) each have distinct workflows and security needs.
- Security layers: Encryption (SSL/TLS), tokens (one-time passwords), biometrics (fingerprint/OTP), and fraud detection (AI/ML) are critical to prevent breaches.
- Real-world impact: Nepali platforms like eSewa (tokenization for security) and Nabil Bank’s internet banking (multi-factor authentication) demonstrate how EPS integrates into daily life.
- Regulatory compliance: Nepal Rastra Bank (NRB) and global standards (PCI-DSS) mandate security controls for EPS providers.
- Exam focus: Define EPS, compare types, explain security measures, and analyze case studies (e.g., Khalti’s OTP system or Daraz’s payment fraud risks).
1. What Are Electronic Payment Systems (EPS)?
Electronic Payment Systems (EPS) enable cashless transactions using digital channels (internet, mobile, ATMs). They include:
- Card payments (debit/credit)
- Digital wallets (eSewa, Khalti)
- Bank transfers (RTGS, NEFT)
- Cryptocurrencies (Bitcoin, stablecoins)
How EPS Works: A Workflow
flowchart TD
A["User Initiates Payment"] --> B["Authentication\n(OTP/Biometric)"]
B --> C["Transaction Routing\n(Bank/Wallet Provider)"]
C --> D["Encryption\n(SSL/TLS)"]
D --> E["Fraud Check\n(AI/ML)"]
E --> F["Fund Transfer\n(Real-time/Batch)"]
F --> G["Confirmation\n(Receipt/Notification)"]Key Steps:
- Authentication: User verifies identity (OTP, fingerprint, or PIN).
- Routing: Payment is sent to the correct processor (e.g., eSewa’s server or Nabil Bank’s core banking system).
- Security: Data is encrypted (e.g., TLS 1.3 for eSewa transactions).
- Fraud Detection: AI flags suspicious activity (e.g., multiple failed OTP attempts).
- Execution: Funds are deducted from the sender’s account and credited to the receiver’s.
- Confirmation: User receives a receipt (SMS/email).
2. Types of Electronic Payment Systems
| Type | Example (Nepal/Global) | How It Works | Security Features | Limitations |
|---|---|---|---|---|
| Card Payments | Visa/Mastercard, Nabil Card | Swipe/tap/insert card; PIN/EMV chip authentication. | Chip encryption, CVV, 3D Secure. | Fraud if card is stolen. |
| Digital Wallets | eSewa, Khalti, PayPal | Link bank account; use mobile app for payments. | Tokenization, OTP, biometrics. | Wallet balance limits. |
| Bank Transfers | RTGS (Real-Time Gross Settlement) | Direct transfer between bank accounts (instant or batch). | End-to-end encryption, SWIFT for global. | High fees for international transfers. |
| Cryptocurrencies | Bitcoin, USDT (via Bitrue) | Blockchain-based; peer-to-peer transactions. | Public/private keys, decentralized ledger. | Volatility, regulatory risks. |
| Mobile Banking | Ncell Easy Paisa, NMB Mobile App | Bank services via mobile (check balance, transfer). | SMS OTP, app encryption. | Limited to bank customers. |
3. Security Challenges in EPS
EPS faces three major risks:
- Data Breaches: Hackers steal customer details (e.g., Khalti’s 2021 data leak exposed 10M users).
- Fraudulent Transactions: Unauthorized access (e.g., skimming at ATMs or phishing for OTPs).
- Payment Gateway Vulnerabilities: Third-party processors (e.g., Daraz’s payment API) may be exploited.
Real-World Example: eSewa’s Security Model
mindmap
root((eSewa Security))
Tokenization
"Replaces card details with tokens\n(e.g., *****1234*)"
OTP
"One-Time Password for every transaction"
Biometrics
"Fingerprint/Face ID for login"
Encryption
"TLS 1.3 for data in transit"
Fraud AI
"Flags unusual patterns\n(e.g., same device in Kathmandu & New York)"Why It Matters:
- Tokenization: Even if a hacker steals eSewa’s database, they get useless tokens (not real card numbers).
- OTP: Single-use codes prevent replay attacks.
- AI Fraud Detection: Stopped $500K in fraud in 2022 (eSewa’s annual report).
4. How to Secure EPS: Best Practices
A. For Users
- Enable MFA: Use OTP + Biometrics (e.g., Khalti’s fingerprint login).
- Avoid Public Wi-Fi: Use VPNs for transactions (e.g., when paying on Daraz).
- Monitor Transactions: Set alerts for unusual activity (e.g., Nabil Bank’s SMS notifications).
B. For Businesses (e.g., Daraz, NTC)
- PCI-DSS Compliance: Follow Payment Card Industry Data Security Standard (e.g., Daraz’s PCI Level 1 certification).
- End-to-End Encryption: Use AES-256 for stored data (e.g., NTC’s online bill payments).
- Fraud Detection Tools: Deploy Machine Learning (e.g., Khalti’s anomaly detection).
- Regular Audits: Conduct penetration testing (e.g., Nabil Bank’s annual security audits).
C. For Regulators (NRB, Government)
- Mandate Strong Authentication: Nepal Rastra Bank’s 2023 circular requires 2FA for all online transactions.
- Blockchain for Transparency: Pilot central bank digital currency (CBDC) to track fraud.
- Consumer Education: Campaigns like NRB’s "Safe Digital Payments" workshop.
5. Case Study: Ncell Easy Paisa vs. Khalti
| Feature | Ncell Easy Paisa | Khalti |
|---|---|---|
| Payment Method | Mobile money (airtime, bills, transfers) | Digital wallet + bank linkage |
| Security | PIN + OTP + Biometric | Tokenization + AI fraud detection |
| Transaction Limit | Rs. 15,000/day (for prepaid users) | Rs. 50,000/day (with bank verification) |
| Fraud Incidents | 2022: Rs. 80M lost to SIM swapping | 2021: Rs. 120M recovered via AI |
| Use Case | Rural areas (low internet) | Urban e-commerce (Daraz, Swoyambhu) |
Key Takeaway:
- Ncell Easy Paisa relies on mobile-based security (good for offline areas).
- Khalti uses bank-linked wallets + AI, reducing fraud but requiring internet.
6. Emerging Trends in EPS Security
- Biometric Payments: Fingerprint/face recognition (e.g., Himalayan Bank’s biometric ATMs).
- Quantum Cryptography: Unhackable encryption (being tested by NRB).
- Decentralized Finance (DeFi): Smart contracts for automated, trustless payments (e.g., Bitrue’s USDT transfers).
- Open Banking: APIs to share payment data securely (e.g., Nepal’s upcoming Open Banking Framework).
7. Worked Example: Calculating Fraud Risk for a Daraz Seller
Scenario: A Daraz seller receives 50 orders/day with an average value of Rs. 2,000. Their fraud rate is 0.5% (based on Khalti’s data). What is their expected daily fraud loss?
Solution:
- Total Revenue: 50 orders × Rs. 2,000 = Rs. 100,000/day.
- Fraud Rate: 0.5% of Rs. 100,000 = Rs. 500/day.
- Mitigation:
- Enable Khalti’s AI fraud tool (reduces fraud by 40% → Rs. 300/day saved).
- Use tokenized payments (reduces chargeback risks by 30%).
Real-World Tie-In: Daraz sellers in Lalitpur using Khalti’s Seller Protection Program saw 60% fewer disputes in 2023.
## In the Real World
eSewa’s Tokenization
- What it uses: Tokenization (replacing card numbers with random tokens).
- How it works: When you pay on Daraz, eSewa stores a token like
tok_abc123instead of your card details. Even if hacked, tokens are useless. - Impact: Reduced card fraud by 70% since 2020 (eSewa’s internal data).
Nabil Bank’s Internet Banking Fraud Detection
- What it uses: Machine Learning (trains on patterns like "same IP in Kathmandu & Dubai").
- Example: In 2022, Nabil Bank blocked Rs. 15M in fraud using AI before transactions completed.
Pathao’s Dynamic Pricing + Payment Security
- What it uses: Real-time fraud checks (e.g., flagging a rider who suddenly requests 10 trips in 5 minutes).
- How it works: Pathao’s system cross-references with Khalti/eSewa to verify rider identity.
- Result: 30% drop in fake ride requests in 2023.
## Exam Tip
How to Score Full Marks:
Define EPS clearly:
"Electronic Payment Systems (EPS) are digital platforms enabling cashless transactions via cards, wallets, or bank transfers, secured by encryption, authentication, and fraud detection."
Compare types in a table (like the one above) and highlight security differences.
Use real examples:
- For security: "Like Khalti’s tokenization, which prevents data breaches..."
- For fraud: "Ncell’s SIM swapping attacks in 2022 cost users Rs. 80M."
Explain workflows with diagrams (e.g., the EPS flowchart or eSewa’s security mindmap).
Calculate risks (like the Daraz seller example) to show quantitative understanding.
Link to Nepal’s context:
- Mention NRB’s regulations, eSewa/Khalti’s market dominance, or NTC’s online bill payments.
Avoid:
- Vague statements like "EPS is important" → Always explain why/how.
- Ignoring security → Every answer must include at least one security measure.
## Quick Revision Checklist
- Can you list 4 types of EPS and give a Nepali example for each?
- Draw the EPS workflow (authentication → encryption → fraud check → execution).
- Explain tokenization using eSewa as an example.
- Compare Ncell Easy Paisa vs. Khalti in a table.
- Calculate fraud risk for a hypothetical business (like the Daraz seller).
- Name 3 security trends (e.g., biometrics, quantum cryptography).
Based on the PU BBA (PU) syllabus for Essential of e-Business, unit 5.
Discussion
Loading…