Download presentation
Presentation is loading. Please wait.
1
e-Commerce Daniel Chromek
2
What is e-Commerce? e-Commerce refers to all commercial transactions in witch one or more stages are processed electronicly
3
Properties of e-Commerce systems
Security (SW,HW) – cryptography, smart cards, POS terminals Cost of transactions – micropayments online/offline systems – third side Anonymity and traceability (coins) Prepaid Pay-now Pay-later
4
Dangers associated with e-Commerce
Communication Component security Establishment of identity
5
Security 1 – thread analysis
Expected likehood of gaining access Damage caused by access Amount of effort required for execute attack Likehood that attacker would be detected
6
Security 2 – symetric cryptography
Chanel
7
Security 3 – asymetric cryptography
Chanel
8
Security 4 – Digital signatures
merchant customer Goods, service
9
Security 5 – One-way hash functions
... dao32ie3qr90wsaa3 95rkq04msp54pwj0 f drl50rea3pr0357ms pjerm338r20smr376 e3053ma49emstuap ...
10
Security 6 – self security
Adhere security informations (ISP recommendations) Antivirus defence Store access gaining means secure Back up Avoid active content (Active X, JavaScript) Look up for encrypion offered by ISP
11
Electronic Payment systems
12
Sending bank Recieving bank Money flow customer merchant
13
Dead e-payment systems
14
First Virtual Start in july '98, no cryptography
Check-like, account based Online, traceable Clients to cybercash
15
Cyber cash Credit card based system (SET protocol)+debit card with authorised shops Cyber coins prepaid system for micropayments Online, traceable Discontinued in 2000 Special SW – Wallet Security: DES+768 bit RSA
16
Milicent Special for micropayments Cash like Online Traceable
Didn't succeed on market
17
Alive electromic payment systems
18
NetCheque Distributed system – NetCheque servers (banks)
Digitaly signed cheques – Kerberos Traceable, online, nonanonym Sigc=[Ecb(CSum_c),Tcb] Sigm=[Emb(CSum_m),Tmb]
19
e-Cash (DigiCash) Founder = David Chaum
Fully anonymed (client) and traceable (blind electronic signatures – RSA blind protocol) System of digital coins – account based cash like Online Related to CAFE smartcard payment system e-Cash Wallet SW Noncostitency with different banks Problem: loss of coins after HDD crush
20
e-Cash 2 - Model -coin verification e-Cash bank -managing accounts
-keeping database Widhdraw/ deposit coins New coins Coins verification Client Wallet Merchant SW Coins payments goods -keep coins -make payments -sell goods -make payments -accept payments
21
SET Standard of Visa and MasterCard PKI and CA used
Developed by GTE Laboratories, IBM, MS, Netscape, SAIC, Terisa and Verisign Not for micropayments (high price for transaction) Online, traceable and account based system
22
SET 2 - model Financial network Recieving bank Emiting bank
1.customer choose goods Financial network 2.customer fill form 3.customer choose type of payment 4.customer send signed payment application to merchant Payment gateway 5. merchant authorise payment in emiting (customer's) bank through recieving (his) bank 6. merchant send goods internet 7. merchant apply for payment in emiting bank customer merchant internet
23
SET 3 – Security aspects Confidentiality
Payment information confidentiality Form information confidentiality Integrity – all document integrity Authentification Customer authentification for PGW and merchant Merchant authentification for PGW and customer PGW authentification for merchant and customer
24
Questions?
25
Sources & download www.bsi.bund.de/english
Jozef Uhler: Elektronické peniaze – diplom work Jaroslav Janáček: Certifikačná autorita – diplom work BSI : e-Commerce, IT Baseline Protections Download site:
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.