2082

BIT403 · TU past paper

E-Commerce 2082 question paper

The complete TU 2082 exam paper for E-Commerce (BIT403), all 12 questions with solved model answers written to the mark scheme.

Past Papers208220812080

Tap a question to open its answer.

  1. 110 marksCapital raising approaches for business moAnswer

    Define business model. Describe the approaches for raising capital for business model.[10]

    Model Answer: Business Model and Capital Raising Approaches

    Definition of Business Model

    A business model is a conceptual framework that describes how an organization creates, delivers, and captures value. It outlines the fundamental logic of how a business operates, generates revenue, and sustains itself in the market.

    Key components of a business model include:

    • Value Proposition: What products/services are offered and what problems they solve
    • Target Market: Who the customers are
    • Revenue Streams: How the business makes money
    • Cost Structure: What resources and expenses are required
    • Key Activities: Core operations necessary to deliver value
    • Partnerships: External relationships and collaborations

    Approaches for Raising Capital for Business Model

    1. Equity Financing

    • Raising funds by selling ownership shares in the business
    • Investors become shareholders and own a portion of the company
    • No repayment obligation, but ownership is diluted
    • Suitable for startups and high-growth ventures
    • Examples: Angel investors, venture capital, initial public offerings (IPO)

    2. Debt Financing

    • Borrowing money that must be repaid with interest
    • Sources include banks, financial institutions, and bonds
    • Business retains full ownership
    • Requires regular repayment and interest payments
    • Suitable for established businesses with predictable cash flows

    3. Retained Earnings

    • Using profits generated by the business itself
    • No external funding required
    • Maintains complete ownership and control
    • Limited by the business's profitability
    • Slower growth but sustainable approach

    4. Crowdfunding

    • Raising small amounts from a large number of people via online platforms
    • Can be equity-based or reward-based
    • Validates market demand before full launch
    • Builds early customer base and brand awareness

    5. Government Grants and Subsidies

    • Non-repayable funds from government agencies
    • Available for specific sectors (technology, agriculture, etc.)
    • No ownership dilution or debt obligation
    • Competitive and may have strict eligibility criteria

    6. Strategic Partnerships and Joint Ventures

    • Collaborating with established companies for funding and resources
    • Shares both capital and operational responsibilities
    • Provides market access and credibility
    • May involve shared ownership and decision-making

    Conclusion: The choice of capital-raising approach depends on the business stage, industry, growth objectives, and the entrepreneur's willingness to share ownership or take on debt obligations.

  2. 210 marksNon-repudiation and accountabilityAnswer

    What is importance of non-repudiation in e-commerce security? How it can be enforced? Explain the security mechanisms used to secure an e-commerce system.[10]

    Model Answer: Non-Repudiation in E-Commerce Security

    Importance of Non-Repudiation in E-Commerce

    Non-repudiation is a critical security requirement in e-commerce that ensures neither party can deny their involvement in a transaction. Its importance includes:

    1. Legal Accountability: Provides legal proof that a transaction occurred, protecting both buyer and seller from false denial of involvement.

    2. Dispute Resolution: Enables resolution of disputes by providing irrefutable evidence of who initiated or completed a transaction.

    3. Trust Building: Establishes confidence in electronic transactions by guaranteeing that parties cannot later claim they did not participate.

    4. Fraud Prevention: Prevents customers from denying purchases and sellers from denying delivery or service provision.

    5. Regulatory Compliance: Meets legal requirements for electronic commerce in many jurisdictions.


    How Non-Repudiation Can Be Enforced

    Non-repudiation is enforced through Digital Signatures:

    Digital Signature Process:

    At Sender's End:

    • Message is hashed using a hash function (e.g., SHA-256)
    • Hash is encrypted using sender's private key
    • Encrypted hash (digital signature) + original message is sent

    At Receiver's End:

    • Receiver decrypts signature using sender's public key to get original hash
    • Receiver independently hashes the received message
    • If both hashes match: authenticity and non-repudiation are confirmed
    • Sender cannot deny sending (only they have private key)

    Mathematical Basis:

    Signature = E(Private_Key, Hash(Message))
    Verification = D(Public_Key, Signature) == Hash(Message)
    

    Security Mechanisms for E-Commerce Systems

    1. Encryption

    • Symmetric Encryption: DES, AES for fast data encryption
    • Asymmetric Encryption: RSA for secure key exchange
    • Protects confidentiality of sensitive data (payment details, personal information)

    2. Authentication

    • Username/Password: Basic user identification
    • Digital Certificates: X.509 certificates verify identity of parties
    • Multi-factor Authentication: Combines passwords with OTP or biometrics
    • Ensures only authorized users access the system

    3. Digital Signatures

    • Provides authentication, integrity, and non-repudiation
    • Uses public key cryptography
    • Proves message origin and that it hasn't been altered

    4. Secure Sockets Layer (SSL) / Transport Layer Security (TLS)

    • Encrypts data in transit between client and server
    • Establishes secure channel for communication
    • Prevents eavesdropping and man-in-the-middle attacks

    5. Firewalls

    • Controls incoming and outgoing network traffic
    • Blocks unauthorized access attempts
    • Monitors suspicious activities

    6. Intrusion Detection Systems (IDS)

    • Monitors network for malicious activities
    • Detects unauthorized access attempts
    • Alerts administrators of security breaches

    7. Access Control

    • Role-based access control (RBAC)
    • Ensures users access only authorized resources
    • Principle of least privilege

    8. Data Integrity Mechanisms

    • Hash functions (MD5, SHA-1, SHA-256)
    • Message Authentication Codes (MAC)
    • Detects unauthorized modification of data

    9. Secure Payment Gateways

    • PCI-DSS compliance for payment card data
    • Tokenization of sensitive payment information
    • Secure processing of financial transactions

    10. Audit Logs and Monitoring

    • Records all transactions and access attempts
    • Enables forensic analysis
    • Helps identify security incidents

    Conclusion

    Non-repudiation through digital signatures combined with comprehensive security mechanisms (encryption, authentication, SSL/TLS, firewalls, and access controls) creates a robust e-commerce security framework that protects all parties involved and ensures transaction integrity and accountability.

  3. 310 marksSET protocol features and participantsAnswer

    What are the SET participants? Explain how dual signature is used in SET protocol? Explain the purchase request operation in SET. [10]

    SET Protocol: Participants, Dual Signature, and Purchase Request

    1. SET Participants

    The Secure Electronic Transaction (SET) protocol involves five main participants:

    1. Cardholder (Customer): The individual making the purchase using a credit or debit card. They initiate transactions and provide payment information.

    2. Merchant: The seller who receives orders from cardholders and requests payment authorization through the SET protocol.

    3. Issuer (Card Issuer Bank): The financial institution that issued the credit/debit card to the cardholder. They authorize or decline payment requests.

    4. Acquirer (Merchant's Bank): The financial institution that maintains the merchant's account and processes payment on behalf of the merchant.

    5. Payment Gateway: The intermediary system that facilitates communication between merchants and acquirers, routing transaction information securely.


    2. Dual Signature in SET Protocol

    Dual Signature is a cryptographic mechanism that provides authentication and non-repudiation while maintaining privacy in SET transactions.

    Purpose:

    • Allows the cardholder to send order information to the merchant and payment information to the payment gateway simultaneously
    • Ensures neither the merchant nor the payment gateway can see both pieces of information
    • Provides proof that the cardholder authorized both the order and payment

    How Dual Signature Works:

    1. Cardholder creates two messages:

      • Order Information (OI): Contains order details sent to merchant
      • Payment Information (PI): Contains payment/card details sent to payment gateway
    2. Hash both messages:

      • H(OI) = hash of order information
      • H(PI) = hash of payment information
    3. Concatenate the hashes:

      • Combined = H(OI) || H(PI)
    4. Create dual signature:

      • DS = E_private[H(H(OI) || H(PI))]
      • Sign the hash of concatenated hashes using cardholder's private key
    5. Send to both parties:

      • To Merchant: OI + DS
      • To Payment Gateway: PI + DS

    Verification:

    • Merchant can verify DS using cardholder's public key and confirm OI integrity
    • Payment Gateway can verify DS using cardholder's public key and confirm PI integrity
    • Neither party can forge or alter the other's information without detection

    3. Purchase Request Operation in SET

    The purchase request is the initial phase where the cardholder sends order details to the merchant.

    Steps in Purchase Request:

    1. Cardholder initiates purchase:

      • Customer selects items and decides to checkout using SET
    2. Cardholder prepares order information:

      • Creates Order Information (OI) containing:
        • Order details (items, quantities, prices)
        • Merchant identifier
        • Transaction ID
        • Amount
    3. Cardholder prepares payment information:

      • Creates Payment Information (PI) containing:
        • Card details (card number, expiry)
        • Cardholder account information
        • Amount
    4. Generate dual signature:

      • Compute H(OI) and H(PI)
      • Create DS = E_private[H(H(OI) || H(PI))]
    5. Send purchase request to merchant:

      • Transmit: OI + DS + Cardholder Certificate
      • Merchant receives order details and can verify signature
    6. Merchant verification:

      • Verifies cardholder's certificate
      • Verifies dual signature using cardholder's public key
      • Confirms order integrity
    7. Merchant forwards to payment gateway:

      • Sends: PI + DS + Cardholder Certificate
      • Payment gateway verifies payment information and signature
    8. Authorization response:

      • Payment gateway authorizes or declines
      • Response sent back through merchant to cardholder

    Key Security Features:

    • Merchant never sees payment information (card details)
    • Payment gateway never sees order details
    • Dual signature prevents repudiation by cardholder
    • All communications are encrypted using certificates
  4. 45 marksTypes of e-commerce by transaction partiesAnswer

    Discuss different types of e-commerce based on transaction parties. [5]

    E-commerce can be classified into several distinct types based on the nature of the parties involved in the transaction. Here are the main categories: - Transactions occur between two or more businesses - Examples: wholesale suppliers se...

  5. 55 marksConsumer behavior models in e-commerceAnswer

    Define consumer behavior models? Why is it essential to address the models in e-commerce marketing? [5]

    Consumer behavior models are conceptual frameworks that explain and predict how consumers make purchasing decisions, interact with products/services, and respond to marketing stimuli. These models map the psychological, social, and econo...

  6. 65 marksEDI layered architectureAnswer

    Explain the EDI layered architecture. [5]

    EDI (Electronic Data Interchange) follows a layered architecture that organizes the components and processes involved in electronic business communication. The architecture typically consists of the following layers: - This is the topmos...

  7. 75 marksElectronic Transaction Act of Nepal sectioAnswer

    Summarize the issues mentioned chapters of electronic transaction act of Nepal. [5]

    Model Answer: Issues in Electronic Transaction Act of Nepal

    Overview

    The Electronic Transaction Act (ETA) of Nepal, enacted in 2063 BS (2006 AD), addresses legal and regulatory issues related to electronic transactions and digital commerce. The following are the key issues covered:

    Main Issues

    • Establishes the validity and legal status of electronic records and signatures
    • Ensures electronic documents have the same legal standing as paper documents
    • Addresses authentication and proof of electronic transactions

    2. Digital Signature and Authentication

    • Provides framework for digital signatures as legally binding
    • Defines requirements for secure digital signatures
    • Establishes certification authorities and their responsibilities
    • Addresses issues of non-repudiation and authenticity

    3. Consumer Protection

    • Protects parties involved in electronic transactions
    • Addresses liability of service providers and intermediaries
    • Ensures transparency in electronic commerce
    • Provides remedies for disputes and grievances

    4. Data Protection and Privacy

    • Safeguards personal information in electronic transactions
    • Addresses confidentiality and security of data
    • Regulates collection, storage, and use of personal data
    • Establishes penalties for unauthorized access

    5. Regulatory Framework

    • Establishes authority for regulation and oversight
    • Defines roles of government agencies
    • Sets standards for electronic transaction systems
    • Addresses licensing and compliance requirements

    6. Dispute Resolution

    • Provides mechanisms for resolving electronic transaction disputes
    • Addresses jurisdiction and applicable law
    • Establishes procedures for complaint handling

    Note: This answer is derived from general knowledge of electronic transaction legislation, as specific reference notes were not provided. For precise details, refer to the actual ETA 2063 BS text.

  8. 85 marksTypes of electronic payment systemsAnswer

    Explain the different types of electronic payment system. [5]

    Electronic payment systems are digital methods of transferring money between parties. The main types are: - Customer uses a credit card (issued by a bank) to make purchases - Payment is processed through card networks (Visa, Mastercard, ...

  9. 95 marksStatic and dynamic catalog buildingAnswer

    How can you build static and dynamic catalogs in an e-commerce system? [5]

    Definition & Approach: A static catalog contains product information that changes infrequently. It is typically built once and remains relatively unchanged until manual updates are performed. Building Method: 1. Data Collection - Gather ...

  10. 105 marksSearch engine marketing definitionAnswer

    What is search engine marketing? Differentiate affiliate marketing from viral marketing. [5]

    Model Answer: Search Engine Marketing and Marketing Differentiation

    Search Engine Marketing (SEM)

    Search Engine Marketing is a digital marketing strategy used to increase the visibility of websites in search engine results pages (SERPs). It involves promoting websites by increasing their visibility through:

    • Paid search advertising - Running sponsored ads on search engines (e.g., Google Ads, Bing Ads)
    • Search Engine Optimization (SEO) - Organic optimization of website content and structure to rank higher naturally
    • Keyword bidding - Advertisers bid on relevant keywords to display ads when users search

    SEM aims to drive targeted traffic to websites from users actively searching for related products, services, or information.


    Differentiation: Affiliate Marketing vs. Viral Marketing

    AspectAffiliate MarketingViral Marketing
    DefinitionPerformance-based marketing where affiliates earn commission for driving sales/leads to a merchant's websiteMarketing strategy where content spreads rapidly through social sharing, creating exponential reach organically
    Cost ModelPay-per-performance (commission-based); advertiser pays only for actual conversionsMinimal direct cost; relies on organic sharing and word-of-mouth
    ControlAdvertiser has direct control over affiliate partners and campaignsLimited control; depends on audience willingness to share content
    ReachTargeted to specific audience segments through affiliate networksUnpredictable but potentially massive reach through exponential sharing
    MechanismDirect referral links; tracking through unique codes/cookiesContent spreads through social networks, email, messaging platforms
    PredictabilityMeasurable and predictable ROIUnpredictable; success depends on content appeal and timing
    ExampleAmazon Associates, commission-based product promotionsMemes, viral videos, trending hashtags spreading organically

    Key Difference: Affiliate marketing is a structured, paid partnership model with measurable results, while viral marketing is an organic, unpredictable phenomenon driven by audience engagement and social sharing.

  11. 115 marksOff-page SEO strategiesAnswer

    Consider you are working as an SEO expert, now explain the possible ways of doing off-page SEO of an e-commerce website. [5]

    Off-page SEO refers to optimization techniques performed outside your website to improve its search engine rankings and online visibility. Here are the key ways to implement off-page SEO for an e-commerce website: - Acquire high-quality ...

  12. 125 marksCollaborative filtering approachesAnswer

    How can you implement collaborative filtering approaches for recommending products in an e-commerce system?' [5]

    Collaborative filtering is a recommendation technique that predicts user preferences based on the assumption that users who agreed in the past will agree in the future. It leverages collective user behavior patterns rather than item cont...