E-Commerce Security
E-Commerce security protects online transactions, customer data, and business operations.
Threats
Phishing, malware, SQL injection, XSS, DDoS, man-in-the-middle, identity theft.
Encryption
Symmetric (AES, DES) and asymmetric (RSA, ECC). Hybrid systems combine both for efficiency and key distribution.
SSL/TLS and HTTPS
Encrypted connections between browsers and servers. Handshake authenticates server, negotiates encryption. HTTPS is mandatory for e-commerce.
Digital Signatures
Verify authenticity and integrity using private key. Digital certificates (X.509) from Certificate Authorities. PKI manages certificates.
Authentication
Passwords, two-factor (OTP/authenticator), biometrics, OAuth/SSO. Multi-factor reduces compromise risk.
Privacy and Compliance
GDPR, CCPA regulations. Consent, right to access/delete, breach notification, data minimisation.
Summary
E-Commerce security requires defence in depth: encryption, secure protocols, authentication, and regulatory compliance.