Unit 3: Cryptography, authentication and firewalls
E-Commerce notes · PTU syllabus (MCOPGE401-18)
On this page
Unit summary
Secure online business rests on cryptography, authentication and firewalls. This unit covers messaging security issues — confidentiality, non-repudiation and access controls — symmetric and asymmetric encryption, public and private key pairs, digital signatures, additional authentication and non-repudiation methods, and firewalls — definition, components, functionality and design factors.
After this unit you can
- Explain messaging security goals
- Compare symmetric and asymmetric encryption
- Explain digital signatures and authentication methods
- Explain firewalls — components, functions and design
PTU syllabus topics
- Messaging security issues (confidentiality, non-repudiation, access controls)
- symmetric and asymmetric encryption
- public/private key pairs
- digital signatures
- additional authentication and non-repudiation methods
- firewall definition
- components
- functionality and design factors
Keys
One shared secret key
Public and private key pair
Speed
Fast
Slower
Key sharing
Difficult and risky
Public key can be shared openly
Example
AES
RSA, digital signatures
Topic 1
Messaging security issues
Confidentiality
Only intended recipients can read (encryption)
Integrity
Message not altered (hashing)
Authentication
Sender is who they claim (certificates, passwords)
Non-repudiation
Sender cannot deny sending (digital signatures)
- Access controls: identification and authentication, authorisation (role-based access), accounting (logs).
Topic 2
Symmetric and asymmetric encryption
Keys
One shared secret key
Pair — public key and private key
Speed
Fast
Slower
Key distribution
Difficult — key must be shared securely
Easy — public key can be published
Examples
AES, DES, 3DES
RSA, ECC
Use
Bulk data encryption
Key exchange, digital signatures
- Hybrid approach (SSL/TLS): asymmetric encryption to exchange a session key, then symmetric encryption for data.
- Public/private key pair: what one key encrypts only the other can decrypt — encrypt with the receiver's public key for confidentiality; sign with the sender's private key for authentication.
Topic 3
Digital signatures and authentication
- 1
Sender hashes the message
SHA-256 digest
- 2
Sender encrypts the hash with private key
Digital signature
- 3
Message + signature sent
- 4
Receiver decrypts signature with sender's public key
- 5
Receiver hashes the message
- 6
Hashes match → authentic and unaltered
- Digital certificates: issued by Certifying Authorities (PKI) binding a public key to an identity; India — Controller of Certifying Authorities under the IT Act.
- Additional authentication methods: passwords and PINs, OTP, two-factor and multi-factor authentication, biometrics (Aadhaar fingerprint/face), smart cards and tokens, Kerberos.
- Non-repudiation methods: digital signatures, time-stamping services, audit logs, trusted third parties.
Topic 4
Firewalls
A firewall is a hardware or software system that monitors and controls incoming and outgoing network traffic based on security rules, separating trusted internal networks from untrusted ones.
Packet-filtering router
Checks IP addresses, ports, protocols
Stateful inspection
Tracks connection states
Application (proxy) gateway
Inspects application-level traffic
Circuit-level gateway
Validates TCP sessions
Next-generation firewall
Deep packet inspection, intrusion prevention, application awareness
DMZ (screened subnet)
Hosts public servers between two firewalls
- Functionality: access control, logging and auditing, NAT (hiding internal addresses), VPN support, content filtering, alerts.
- Design factors: security policy (default deny), network architecture (DMZ), performance and scalability, redundancy, ease of management, cost, regular updating and monitoring; firewalls do not stop insider threats or malware in permitted traffic — layered security is needed.
Key terms
- Encryption
- Converting plaintext into ciphertext
- Public key
- Key published for encryption or verifying signatures
- Hash function
- Algorithm producing a fixed-length digest of a message
- Digital certificate
- Electronic document binding a public key to an identity
- Firewall
- System controlling network traffic using security rules
Quick revision
- Goals: confidentiality, integrity, authentication, non-repudiation; access controls.
- Symmetric (AES) vs asymmetric (RSA); hybrid in TLS.
- Digital signature: hash + private key; verify with public key.
- Authentication: passwords, OTP, MFA, biometrics, tokens.
- Firewalls: packet filter, stateful, proxy, NGFW, DMZ; design factors.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is non-repudiation?
- Q2.Distinguish symmetric and asymmetric encryption.
- Q3.How is a digital signature verified?
- Q4.What is a digital certificate?
- Q5.What is a firewall?
- Q6.What is a DMZ?
Long-answer questions
- Q1.Explain messaging security issues in e-commerce.
- Q2.Explain symmetric and asymmetric encryption and public/private key pairs.
- Q3.Explain digital signatures and other authentication and non-repudiation methods.
- Q4.Explain firewalls — components, functionality and design factors.
Stuck on this unit?
Message SBS on WhatsApp for help with E-Commerce, or to ask about studying M.Com at Synetic.
