Beyond "web of trust": Enabling P2P E-commerce
نویسندگان
چکیده
The huge success of eBay has proven the demand for customer-to-customer (C2C) electronic commerce. eBay is a centralized infrastructure with all its scalability problems (network bandwidth, server load, availability, etc.). In this paper we argue that C2C e-commerce is an application domain that maps naturally onto the emergent field of P2P systems simply by its underlying interaction model of customers, i.e., peers. This offers the opportunity to take P2P systems beyond mere file sharing systems into interesting new application domains. The long-term goal would be to design a fully functional decentralized system which resembles eBay without eBay’s dedicated, centralized infrastructure. Since security (authenticity, non-repudiation, trust, etc.) is key to any e-commerce infrastructure, our envisioned P2P e-commerce platform has to address this adequately. As the first step in this direction we present an approach for a completely decentralized P2P public key infrastructure (PKI) which can serve as the basis for higherlevel security service. In contrast to other systems in this area, such as PGP which uses a “web of trust” concept, we use a statistical approach which allows us to provide an analytical model with provable guarantees, and quantify the behavior and specific properties of the PKI. To justify our claims we provide a first-order analysis and discuss its resilience against various known threats and attack scenarios. In support of our belief that C2C E-commerce is one of the potential killer applications of the emerging structured P2P systems, we provide a layered model for P2P E-commerce, demonstrating the dependencies of various security related issues that can be built on top of a decentralized PKI. ∗The work presented in this paper was supported (in part) by the National Competence Center in Research on Mobile Information and Communication Systems (NCCR-MICS), a center supported by the Swiss National Science Foundation under grant number 5005-67322.
منابع مشابه
A Security and Trust Framework for Agent-based P2P E-commerce
P2P based e-commerce (EC) is becoming increasingly significant where security and trust are two of the most critical issues. This paper discusses and proposes a secure infrastructure with peer certificates aiming at easing the involvement of CA (Certificate Authority) and enabling the framework for securing peers and the communication between them. This paper also proposes a novel two-phase tru...
متن کاملProviding Trust and Reputation in Peer-to-Peer Networks
The Internet has already set its users free of any kind of building infrastructure. It has evolved beyond email, content, and e-commerce, becoming a true platform that combines the qualities of service of enterprise computing with the ability to share resources across the web. Moreover, Internet is becoming more and more distributed, and so are the expectations for its aligning protocols. Accor...
متن کاملSecure Community Trust Stores for Peer-to-Peer e-Commerce Applications Using Cloud Services
P2P e-commerce applications have lower operational costs and inherently more scalable than conventional client-server online trading. Community Trust Stores (CTS) provide reliable and secure storage services for peers involved in P2P e-trading by storing trust data for the peers. Freely available cloud services can host the Community Trust Store and provide 24/7 availability to participating tr...
متن کاملThe Roadmap of Trust and Trust Evaluation in Web Applications and Web Services
In the 1980s and 1990s, the issue of trust in many aspects of life has drawn much attention in a significant number of studies in social science. Nowadays, with the development of Web applications, trust evaluation has become a significant and important issue, especially when a client has to select a trustworthy one from a pool of unknown service providers. An effective and efficient trust eval...
متن کاملA New Trust Model for B2C E-Commerce Based on 3D User Interfaces
Lack of trust is one of the key bottle necks in e-commerce development. Nowadays many advanced technologies are trying to address the trust issues in e-commerce. One among them suggests using suitable user interfaces. This paper investigates the functionality and capabilities of 3D graphical user interfaces in regard to trust building in the customers of next generation of B2C e-commerce websit...
متن کامل