e-Commerce Daniel Chromek
What is e-Commerce? e-Commerce refers to all commercial transactions in witch one or more stages are processed electronicly
Properties of e-Commerce systems Security (SW,HW) – cryptography, smart cards, POS terminals Cost of transactions – micropayments online/offline systems – third side Anonymity and traceability (coins) Prepaid Pay-now Pay-later
Dangers associated with e-Commerce Communication Component security Establishment of identity
Security 1 – thread analysis Expected likehood of gaining access Damage caused by access Amount of effort required for execute attack Likehood that attacker would be detected
Security 2 – symetric cryptography Chanel
Security 3 – asymetric cryptography Chanel
Security 4 – Digital signatures merchant customer Goods, service
Security 5 – One-way hash functions ... dao32ie3qr90wsaa3 95rkq04msp54pwj0 f drl50rea3pr0357ms pjerm338r20smr376 e3053ma49emstuap ...
Security 6 – self security Adhere security informations (ISP recommendations) Antivirus defence Store access gaining means secure Back up Avoid active content (Active X, JavaScript) Look up for encrypion offered by ISP
Electronic Payment systems
Sending bank Recieving bank Money flow customer merchant
Dead e-payment systems
First Virtual Start in july '98, no cryptography Check-like, account based Online, traceable Clients to cybercash
Cyber cash Credit card based system (SET protocol)+debit card with authorised shops Cyber coins prepaid system for micropayments Online, traceable Discontinued in 2000 Special SW – Wallet Security: DES+768 bit RSA
Milicent Special for micropayments Cash like Online Traceable Didn't succeed on market
Alive electromic payment systems
NetCheque Distributed system – NetCheque servers (banks) Digitaly signed cheques – Kerberos Traceable, online, nonanonym Sigc=[Ecb(CSum_c),Tcb] Sigm=[Emb(CSum_m),Tmb]
e-Cash (DigiCash) Founder = David Chaum Fully anonymed (client) and traceable (blind electronic signatures – RSA blind protocol) System of digital coins – account based cash like Online Related to CAFE smartcard payment system e-Cash Wallet SW Noncostitency with different banks Problem: loss of coins after HDD crush
e-Cash 2 - Model -coin verification e-Cash bank -managing accounts -keeping database Widhdraw/ deposit coins New coins Coins verification Client Wallet Merchant SW Coins payments goods -keep coins -make payments -sell goods -make payments -accept payments
SET Standard of Visa and MasterCard PKI and CA used Developed by GTE Laboratories, IBM, MS, Netscape, SAIC, Terisa and Verisign Not for micropayments (high price for transaction) Online, traceable and account based system
SET 2 - model Financial network Recieving bank Emiting bank 1.customer choose goods Financial network 2.customer fill form 3.customer choose type of payment 4.customer send signed payment application to merchant Payment gateway 5. merchant authorise payment in emiting (customer's) bank through recieving (his) bank 6. merchant send goods internet 7. merchant apply for payment in emiting bank customer merchant internet
SET 3 – Security aspects Confidentiality Payment information confidentiality Form information confidentiality Integrity – all document integrity Authentification Customer authentification for PGW and merchant Merchant authentification for PGW and customer PGW authentification for merchant and customer
Questions?
Sources & download www.bsi.bund.de/english Jozef Uhler: Elektronické peniaze – diplom work Jaroslav Janáček: Certifikačná autorita – diplom work BSI : e-Commerce, IT Baseline Protections Download site: www.dundee.szm.sk/Projekty/projekty.html