A Formal Security Modeling and Analysis in B2B e-commerce

نویسندگان

  • Han Zhang
  • Gerald Weber
چکیده

Despite the flourishing research on formal modeling and analysis of privacy and authentication issues in E-commerce, little research concentrates on the possible security risk due to business logic specification. In E-commerce systems, an aspect of this logic is to promise fairness. As the feature ensuring parties conduct their business to their mutual moral standards, fairness is one of the paramount features for E-commerce payment systems. In this case study of the AARN payment system, we apply form-oriented analysis to formally model the simple business logic behind this way of arranging payment. The model solves a fair exchange issue for security purposes at the business logic level, which changes further design and implementation for the payment system. It is the first time that Data Type Interchange Model diagram and other models in form-oriented analysis method have been applied in security analysis. This form-oriented analysis method helps designers not only on security analysis, but also on understanding and communication between business experts and software designers.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Xml Data Modeling Concepts in B2b Catalog Standards

The transmission of electronic product catalogs using e-business standards belongs to the first and most common applications of XML in B2B e-commerce. Suppliers create electronic catalogs in standardized formats and transfer them to their customers. Eventually the receiving enterprises import the data into e-market places and e-procurement systems. In both cases a transformation of relational d...

متن کامل

B2B Negotiation Support: The Need for a Communication Perspective

Negotiation support is an important challenge for business-to-business e-commerce that is still poorly supported in current information systems. One reason is that negotiation processes are much harder to formalize than the business processes in the fulfilment phase. The goal of this paper is to provide the basis for a formal analysis of different types of electronic negotiations which can help...

متن کامل

Simulation analysis of protected B2B e-commerce processes

In this paper a simulation analysis of certain trust models (complex PKI architectures) with regard to the security support of B2B applications on the Internet is presented. The objective of such an analysis has been the choice of the most efficient PKI architecture and a solution of the cryptographic interoperability problem. A simulation model of protected B2B e-commerce has also been present...

متن کامل

The Significance of XML

Although the overall investment in information technology (IT) decreased during the first few years of the 21st century, B2B e-commerce continued to expand at a rapid rate (Lim & Wen, 2002). The expansion of B2B e-commerce has been based to a large extent on accounting and enterprise-wide information systems (EISs) that permit electronic data transmission and execution of transactions in an eff...

متن کامل

Impact of Technology-Related Environment Issues on Trust in B2B E-Commerce

The virtual environment of B2B e-commerce interactions has been considered to be a barrier in building trust of trading partners. There is adequate empirical evidence that supports the relationship between various trust related technology issues such as security, privacy, authentication, etc. However, there is dearth of evidence confirming the causal relationship between environment related tru...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2001