Skip to main content

Security Schemes in Electronic Payment Systems

Introduction 
Secure electronic function transfer is crucial to e-commerce. In order to ensure the integrity and security of each electronic transaction and other EPSS utilize some or all of the following security measures and technologies directly related to EPSS: 
1) Authentication  
2) Public Key Cryptography  
3) Digital Signatures  
4) Certificate  
5) Certificate Authorities  
6) Secure Socket Layers(SSL)  
7) Secure Hypertext Transfer Protocol(S-HTTP)
 
Electronic Payment Protocols
Securities schemes are implemented by protocols: 
1) Secure Socket Layer (SSL): Netscape communication has proposed a protocol for providing data security layered between high-level application protocols and TCP/IP. This security protocol, called SSL, provides data encryption, server authentication, message integrity and optional client authentication for a TCP/IP connection.
 
SSL provides a security "handshake" to initiate the TCP/IP connection .This handshake results in the client and server agreeing on the level of security that they will use and fulfills any authentication requirements for the connection. Therefore SSL's only role is to encrypt and decrypt the message stream.
 
This protocol fully encrypts all the information in both the HTTP request and the HTTP response, including the URL the client is requesting.

2) Secure Hypertext Transmission Protocol (S-HTTP): S-HTTP was Sn developed for commerce Net- a consortium of companies promoting the  Bestablishment of electronic commerce on the internet. S-HTTP supports a B variety of security mechanisms to HTTP clients and servers, providing the security service options appropriate to the wide range of potential end uses possible on the web. The protocol provides symmetric capabilities to both client and server. 
 
To ensure a secure conversation between a web client and server, S-HTTP works by negotiating the type of encryption scheme used between client and server. Several cryptographic message format standards can be incorporated into S-HTTP clients and servers. S-HTTP does not require client-side public- key certificates. This is significant because it means that spontaneous private transactions can occur without requiring individual users to have an  established public key.
 
One advantages of S-HTTP is that it supports end-to-end secure transaction. This means that multiple encryption/decryption need not be done at every intermediate point.

3) Secure Electronic Transaction (SET): SET has been developed mainly by the credit card industry to secure payment card transactions over open networks. SET has been published as open specification for the industry. The current version of SET was designed for common desktop PCs as the typical user terminal, and with the internet as the transport network.

Previous Next

 

Comments

Popular Post

E-Procurement Cycle

Figure 2.6 illustrates the different steps associated with the overall procurement cycle, from the order placement to the accounts payable, in steps through a web based e-commerce network. It includes customers' inventory and supplier information and is readily accessible at any time and from everywhere.  E-procurement allows two-way communication of real-time financial and purchasing information. Management at both the buying and selling end can see what is happening at any given moment and identify trends and problems. A shorter purchasing cycle enables companies to maintain lower inventory levels and respond more quickly to stock-outs. Previous Next

Business Strategy - Strategic Planning Cycle

E-business competitive strategy is normally formed and implemented according to a planning cycle which is called strategic planning cycle . There are four stages in this planning cycle as shown in figure 1.19: Industry and Competitive Analysis It aims to identifying those factors on which the success of an electronic commerce project or business would depend. One way of doing that is to carry out SWOT analysis and study your business as well as the business of competitors. Analysis of online competitor businesses is relatively easy since they are just a few clicks away on the web.  Strategy Formulation Based upen study of internal and external business environment and in light of a company's strengths and weaknesses, a competitive business strategy is formed. It may be a strategy of cost leadership, product differentiation or focus. One can also identify ways how information technology can be used to implement/enforce such strategy. The inputs to the strategy formulation process ar...

Disadvantages of EDI

1), Operating Procedures : Since EDI is a structured way of working, companies usually change operating procedures.  2) Production and Purchasing Decisions : Responsibilities may have to be changed during the introduction of EDI system. Unless this system and the links with other systems are managed well, it is not possible for the data processing department to become involved in production and purchasing decisions.  3) Transparent : Less transparent than paper-based systems.  4) Flexibility : Certain EDI systems are highly flexible, others are very simple to implement.  5) High Costs : Applications are costing to develop and operate; especially new entrants find this more difficult to have EDI. Many small companies are facing resources problems in getting starter with the initial implementation of EDI system. It is beyond the resources these companies to invest tens or hundreds of thousands of dollars in setting and implementation costs, as well as weeks of personne...