Unit 3 of 4 · M.Com Sem 4

Unit 3: Cryptography, authentication and firewalls

E-Commerce notes · PTU syllabus (MCOPGE401-18)

3 min read4 topics10 exam questions
On this page
  1. Unit summary
  2. Messaging security issues
  3. Symmetric and asymmetric encryption
  4. Digital signatures and authentication
  5. Firewalls
  6. Key terms
  7. Quick revision
  8. Important questions

Unit summary

Secure online business rests on cryptography, authentication and firewalls. This unit covers messaging security issues — confidentiality, non-repudiation and access controls — symmetric and asymmetric encryption, public and private key pairs, digital signatures, additional authentication and non-repudiation methods, and firewalls — definition, components, functionality and design factors.

After this unit you can

  • Explain messaging security goals
  • Compare symmetric and asymmetric encryption
  • Explain digital signatures and authentication methods
  • Explain firewalls — components, functions and design

PTU syllabus topics

  • Messaging security issues (confidentiality, non-repudiation, access controls)
  • symmetric and asymmetric encryption
  • public/private key pairs
  • digital signatures
  • additional authentication and non-repudiation methods
  • firewall definition
  • components
  • functionality and design factors
ComparisonSymmetric vs asymmetric encryption
Symmetric
Asymmetric

Keys

One shared secret key

Public and private key pair

Speed

Fast

Slower

Key sharing

Difficult and risky

Public key can be shared openly

Example

AES

RSA, digital signatures

1

Topic 1

Messaging security issues

FrameworkSecurity goals for messages
  • Confidentiality

    Only intended recipients can read (encryption)

  • Integrity

    Message not altered (hashing)

  • Authentication

    Sender is who they claim (certificates, passwords)

  • Non-repudiation

    Sender cannot deny sending (digital signatures)

  • Access controls: identification and authentication, authorisation (role-based access), accounting (logs).
2

Topic 2

Symmetric and asymmetric encryption

ComparisonSymmetric vs asymmetric encryption
Symmetric (secret key)
Asymmetric (public key)

Keys

One shared secret key

Pair — public key and private key

Speed

Fast

Slower

Key distribution

Difficult — key must be shared securely

Easy — public key can be published

Examples

AES, DES, 3DES

RSA, ECC

Use

Bulk data encryption

Key exchange, digital signatures

  • Hybrid approach (SSL/TLS): asymmetric encryption to exchange a session key, then symmetric encryption for data.
  • Public/private key pair: what one key encrypts only the other can decrypt — encrypt with the receiver's public key for confidentiality; sign with the sender's private key for authentication.
3

Topic 3

Digital signatures and authentication

ProcessCreating and verifying a digital signature
  1. 1

    Sender hashes the message

    SHA-256 digest

  2. 2

    Sender encrypts the hash with private key

    Digital signature

  3. 3

    Message + signature sent

  4. 4

    Receiver decrypts signature with sender's public key

  5. 5

    Receiver hashes the message

  6. 6

    Hashes match → authentic and unaltered

  • Digital certificates: issued by Certifying Authorities (PKI) binding a public key to an identity; India — Controller of Certifying Authorities under the IT Act.
  • Additional authentication methods: passwords and PINs, OTP, two-factor and multi-factor authentication, biometrics (Aadhaar fingerprint/face), smart cards and tokens, Kerberos.
  • Non-repudiation methods: digital signatures, time-stamping services, audit logs, trusted third parties.
4

Topic 4

Firewalls

A firewall is a hardware or software system that monitors and controls incoming and outgoing network traffic based on security rules, separating trusted internal networks from untrusted ones.

ClassificationFirewall components and types
Firewalls
  • Packet-filtering router

    Checks IP addresses, ports, protocols

  • Stateful inspection

    Tracks connection states

  • Application (proxy) gateway

    Inspects application-level traffic

  • Circuit-level gateway

    Validates TCP sessions

  • Next-generation firewall

    Deep packet inspection, intrusion prevention, application awareness

  • DMZ (screened subnet)

    Hosts public servers between two firewalls

  • Functionality: access control, logging and auditing, NAT (hiding internal addresses), VPN support, content filtering, alerts.
  • Design factors: security policy (default deny), network architecture (DMZ), performance and scalability, redundancy, ease of management, cost, regular updating and monitoring; firewalls do not stop insider threats or malware in permitted traffic — layered security is needed.

Key terms

Encryption
Converting plaintext into ciphertext
Public key
Key published for encryption or verifying signatures
Hash function
Algorithm producing a fixed-length digest of a message
Digital certificate
Electronic document binding a public key to an identity
Firewall
System controlling network traffic using security rules

Quick revision

  • Goals: confidentiality, integrity, authentication, non-repudiation; access controls.
  • Symmetric (AES) vs asymmetric (RSA); hybrid in TLS.
  • Digital signature: hash + private key; verify with public key.
  • Authentication: passwords, OTP, MFA, biometrics, tokens.
  • Firewalls: packet filter, stateful, proxy, NGFW, DMZ; design factors.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.What is non-repudiation?
  2. Q2.Distinguish symmetric and asymmetric encryption.
  3. Q3.How is a digital signature verified?
  4. Q4.What is a digital certificate?
  5. Q5.What is a firewall?
  6. Q6.What is a DMZ?

Long-answer questions

  1. Q1.Explain messaging security issues in e-commerce.
  2. Q2.Explain symmetric and asymmetric encryption and public/private key pairs.
  3. Q3.Explain digital signatures and other authentication and non-repudiation methods.
  4. Q4.Explain firewalls — components, functionality and design factors.

Stuck on this unit?

Message SBS on WhatsApp for help with E-Commerce, or to ask about studying M.Com at Synetic.

WhatsApp us