BIT403 · TU past paper
E-Commerce 2082 question paper
The complete TU 2082 exam paper for E-Commerce (BIT403), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksCapital raising approaches for business moHideAnswer
Define business model. Describe the approaches for raising capital for business model.[10]
Model Answer: Business Model and Capital Raising Approaches
Definition of Business Model
A business model is a conceptual framework that describes how an organization creates, delivers, and captures value. It outlines the fundamental logic of how a business operates, generates revenue, and sustains itself in the market.
Key components of a business model include:
- Value Proposition: What products/services are offered and what problems they solve
- Target Market: Who the customers are
- Revenue Streams: How the business makes money
- Cost Structure: What resources and expenses are required
- Key Activities: Core operations necessary to deliver value
- Partnerships: External relationships and collaborations
Approaches for Raising Capital for Business Model
1. Equity Financing
- Raising funds by selling ownership shares in the business
- Investors become shareholders and own a portion of the company
- No repayment obligation, but ownership is diluted
- Suitable for startups and high-growth ventures
- Examples: Angel investors, venture capital, initial public offerings (IPO)
2. Debt Financing
- Borrowing money that must be repaid with interest
- Sources include banks, financial institutions, and bonds
- Business retains full ownership
- Requires regular repayment and interest payments
- Suitable for established businesses with predictable cash flows
3. Retained Earnings
- Using profits generated by the business itself
- No external funding required
- Maintains complete ownership and control
- Limited by the business's profitability
- Slower growth but sustainable approach
4. Crowdfunding
- Raising small amounts from a large number of people via online platforms
- Can be equity-based or reward-based
- Validates market demand before full launch
- Builds early customer base and brand awareness
5. Government Grants and Subsidies
- Non-repayable funds from government agencies
- Available for specific sectors (technology, agriculture, etc.)
- No ownership dilution or debt obligation
- Competitive and may have strict eligibility criteria
6. Strategic Partnerships and Joint Ventures
- Collaborating with established companies for funding and resources
- Shares both capital and operational responsibilities
- Provides market access and credibility
- May involve shared ownership and decision-making
Conclusion: The choice of capital-raising approach depends on the business stage, industry, growth objectives, and the entrepreneur's willingness to share ownership or take on debt obligations.
- 210 marksNon-repudiation and accountabilityHideAnswer
What is importance of non-repudiation in e-commerce security? How it can be enforced? Explain the security mechanisms used to secure an e-commerce system.[10]
Model Answer: Non-Repudiation in E-Commerce Security
Importance of Non-Repudiation in E-Commerce
Non-repudiation is a critical security requirement in e-commerce that ensures neither party can deny their involvement in a transaction. Its importance includes:
-
Legal Accountability: Provides legal proof that a transaction occurred, protecting both buyer and seller from false denial of involvement.
-
Dispute Resolution: Enables resolution of disputes by providing irrefutable evidence of who initiated or completed a transaction.
-
Trust Building: Establishes confidence in electronic transactions by guaranteeing that parties cannot later claim they did not participate.
-
Fraud Prevention: Prevents customers from denying purchases and sellers from denying delivery or service provision.
-
Regulatory Compliance: Meets legal requirements for electronic commerce in many jurisdictions.
How Non-Repudiation Can Be Enforced
Non-repudiation is enforced through Digital Signatures:
Digital Signature Process:
At Sender's End:
- Message is hashed using a hash function (e.g., SHA-256)
- Hash is encrypted using sender's private key
- Encrypted hash (digital signature) + original message is sent
At Receiver's End:
- Receiver decrypts signature using sender's public key to get original hash
- Receiver independently hashes the received message
- If both hashes match: authenticity and non-repudiation are confirmed
- Sender cannot deny sending (only they have private key)
Mathematical Basis:
Signature = E(Private_Key, Hash(Message)) Verification = D(Public_Key, Signature) == Hash(Message)
Security Mechanisms for E-Commerce Systems
1. Encryption
- Symmetric Encryption: DES, AES for fast data encryption
- Asymmetric Encryption: RSA for secure key exchange
- Protects confidentiality of sensitive data (payment details, personal information)
2. Authentication
- Username/Password: Basic user identification
- Digital Certificates: X.509 certificates verify identity of parties
- Multi-factor Authentication: Combines passwords with OTP or biometrics
- Ensures only authorized users access the system
3. Digital Signatures
- Provides authentication, integrity, and non-repudiation
- Uses public key cryptography
- Proves message origin and that it hasn't been altered
4. Secure Sockets Layer (SSL) / Transport Layer Security (TLS)
- Encrypts data in transit between client and server
- Establishes secure channel for communication
- Prevents eavesdropping and man-in-the-middle attacks
5. Firewalls
- Controls incoming and outgoing network traffic
- Blocks unauthorized access attempts
- Monitors suspicious activities
6. Intrusion Detection Systems (IDS)
- Monitors network for malicious activities
- Detects unauthorized access attempts
- Alerts administrators of security breaches
7. Access Control
- Role-based access control (RBAC)
- Ensures users access only authorized resources
- Principle of least privilege
8. Data Integrity Mechanisms
- Hash functions (MD5, SHA-1, SHA-256)
- Message Authentication Codes (MAC)
- Detects unauthorized modification of data
9. Secure Payment Gateways
- PCI-DSS compliance for payment card data
- Tokenization of sensitive payment information
- Secure processing of financial transactions
10. Audit Logs and Monitoring
- Records all transactions and access attempts
- Enables forensic analysis
- Helps identify security incidents
Conclusion
Non-repudiation through digital signatures combined with comprehensive security mechanisms (encryption, authentication, SSL/TLS, firewalls, and access controls) creates a robust e-commerce security framework that protects all parties involved and ensures transaction integrity and accountability.
-
- 310 marksSET protocol features and participantsHideAnswer
What are the SET participants? Explain how dual signature is used in SET protocol? Explain the purchase request operation in SET. [10]
SET Protocol: Participants, Dual Signature, and Purchase Request
1. SET Participants
The Secure Electronic Transaction (SET) protocol involves five main participants:
-
Cardholder (Customer): The individual making the purchase using a credit or debit card. They initiate transactions and provide payment information.
-
Merchant: The seller who receives orders from cardholders and requests payment authorization through the SET protocol.
-
Issuer (Card Issuer Bank): The financial institution that issued the credit/debit card to the cardholder. They authorize or decline payment requests.
-
Acquirer (Merchant's Bank): The financial institution that maintains the merchant's account and processes payment on behalf of the merchant.
-
Payment Gateway: The intermediary system that facilitates communication between merchants and acquirers, routing transaction information securely.
2. Dual Signature in SET Protocol
Dual Signature is a cryptographic mechanism that provides authentication and non-repudiation while maintaining privacy in SET transactions.
Purpose:
- Allows the cardholder to send order information to the merchant and payment information to the payment gateway simultaneously
- Ensures neither the merchant nor the payment gateway can see both pieces of information
- Provides proof that the cardholder authorized both the order and payment
How Dual Signature Works:
-
Cardholder creates two messages:
- Order Information (OI): Contains order details sent to merchant
- Payment Information (PI): Contains payment/card details sent to payment gateway
-
Hash both messages:
- H(OI) = hash of order information
- H(PI) = hash of payment information
-
Concatenate the hashes:
- Combined = H(OI) || H(PI)
-
Create dual signature:
- DS = E_private[H(H(OI) || H(PI))]
- Sign the hash of concatenated hashes using cardholder's private key
-
Send to both parties:
- To Merchant: OI + DS
- To Payment Gateway: PI + DS
Verification:
- Merchant can verify DS using cardholder's public key and confirm OI integrity
- Payment Gateway can verify DS using cardholder's public key and confirm PI integrity
- Neither party can forge or alter the other's information without detection
3. Purchase Request Operation in SET
The purchase request is the initial phase where the cardholder sends order details to the merchant.
Steps in Purchase Request:
-
Cardholder initiates purchase:
- Customer selects items and decides to checkout using SET
-
Cardholder prepares order information:
- Creates Order Information (OI) containing:
- Order details (items, quantities, prices)
- Merchant identifier
- Transaction ID
- Amount
- Creates Order Information (OI) containing:
-
Cardholder prepares payment information:
- Creates Payment Information (PI) containing:
- Card details (card number, expiry)
- Cardholder account information
- Amount
- Creates Payment Information (PI) containing:
-
Generate dual signature:
- Compute H(OI) and H(PI)
- Create DS = E_private[H(H(OI) || H(PI))]
-
Send purchase request to merchant:
- Transmit: OI + DS + Cardholder Certificate
- Merchant receives order details and can verify signature
-
Merchant verification:
- Verifies cardholder's certificate
- Verifies dual signature using cardholder's public key
- Confirms order integrity
-
Merchant forwards to payment gateway:
- Sends: PI + DS + Cardholder Certificate
- Payment gateway verifies payment information and signature
-
Authorization response:
- Payment gateway authorizes or declines
- Response sent back through merchant to cardholder
Key Security Features:
- Merchant never sees payment information (card details)
- Payment gateway never sees order details
- Dual signature prevents repudiation by cardholder
- All communications are encrypted using certificates
-
- 45 marksTypes of e-commerce by transaction partiesHideAnswer
Discuss different types of e-commerce based on transaction parties. [5]
E-commerce can be classified into several distinct types based on the nature of the parties involved in the transaction. Here are the main categories: - Transactions occur between two or more businesses - Examples: wholesale suppliers se...
- 55 marksConsumer behavior models in e-commerceHideAnswer
Define consumer behavior models? Why is it essential to address the models in e-commerce marketing? [5]
Consumer behavior models are conceptual frameworks that explain and predict how consumers make purchasing decisions, interact with products/services, and respond to marketing stimuli. These models map the psychological, social, and econo...
- 65 marksEDI layered architectureHideAnswer
Explain the EDI layered architecture. [5]
EDI (Electronic Data Interchange) follows a layered architecture that organizes the components and processes involved in electronic business communication. The architecture typically consists of the following layers: - This is the topmos...
- 75 marksElectronic Transaction Act of Nepal sectioHideAnswer
Summarize the issues mentioned chapters of electronic transaction act of Nepal. [5]
Model Answer: Issues in Electronic Transaction Act of Nepal
Overview
The Electronic Transaction Act (ETA) of Nepal, enacted in 2063 BS (2006 AD), addresses legal and regulatory issues related to electronic transactions and digital commerce. The following are the key issues covered:
Main Issues
1. Legal Recognition of Electronic Documents
- Establishes the validity and legal status of electronic records and signatures
- Ensures electronic documents have the same legal standing as paper documents
- Addresses authentication and proof of electronic transactions
2. Digital Signature and Authentication
- Provides framework for digital signatures as legally binding
- Defines requirements for secure digital signatures
- Establishes certification authorities and their responsibilities
- Addresses issues of non-repudiation and authenticity
3. Consumer Protection
- Protects parties involved in electronic transactions
- Addresses liability of service providers and intermediaries
- Ensures transparency in electronic commerce
- Provides remedies for disputes and grievances
4. Data Protection and Privacy
- Safeguards personal information in electronic transactions
- Addresses confidentiality and security of data
- Regulates collection, storage, and use of personal data
- Establishes penalties for unauthorized access
5. Regulatory Framework
- Establishes authority for regulation and oversight
- Defines roles of government agencies
- Sets standards for electronic transaction systems
- Addresses licensing and compliance requirements
6. Dispute Resolution
- Provides mechanisms for resolving electronic transaction disputes
- Addresses jurisdiction and applicable law
- Establishes procedures for complaint handling
Note: This answer is derived from general knowledge of electronic transaction legislation, as specific reference notes were not provided. For precise details, refer to the actual ETA 2063 BS text.
- 85 marksTypes of electronic payment systemsHideAnswer
Explain the different types of electronic payment system. [5]
Electronic payment systems are digital methods of transferring money between parties. The main types are: - Customer uses a credit card (issued by a bank) to make purchases - Payment is processed through card networks (Visa, Mastercard, ...
- 95 marksStatic and dynamic catalog buildingHideAnswer
How can you build static and dynamic catalogs in an e-commerce system? [5]
Definition & Approach: A static catalog contains product information that changes infrequently. It is typically built once and remains relatively unchanged until manual updates are performed. Building Method: 1. Data Collection - Gather ...
- 105 marksSearch engine marketing definitionHideAnswer
What is search engine marketing? Differentiate affiliate marketing from viral marketing. [5]
Model Answer: Search Engine Marketing and Marketing Differentiation
Search Engine Marketing (SEM)
Search Engine Marketing is a digital marketing strategy used to increase the visibility of websites in search engine results pages (SERPs). It involves promoting websites by increasing their visibility through:
- Paid search advertising - Running sponsored ads on search engines (e.g., Google Ads, Bing Ads)
- Search Engine Optimization (SEO) - Organic optimization of website content and structure to rank higher naturally
- Keyword bidding - Advertisers bid on relevant keywords to display ads when users search
SEM aims to drive targeted traffic to websites from users actively searching for related products, services, or information.
Differentiation: Affiliate Marketing vs. Viral Marketing
Aspect Affiliate Marketing Viral Marketing Definition Performance-based marketing where affiliates earn commission for driving sales/leads to a merchant's website Marketing strategy where content spreads rapidly through social sharing, creating exponential reach organically Cost Model Pay-per-performance (commission-based); advertiser pays only for actual conversions Minimal direct cost; relies on organic sharing and word-of-mouth Control Advertiser has direct control over affiliate partners and campaigns Limited control; depends on audience willingness to share content Reach Targeted to specific audience segments through affiliate networks Unpredictable but potentially massive reach through exponential sharing Mechanism Direct referral links; tracking through unique codes/cookies Content spreads through social networks, email, messaging platforms Predictability Measurable and predictable ROI Unpredictable; success depends on content appeal and timing Example Amazon Associates, commission-based product promotions Memes, viral videos, trending hashtags spreading organically Key Difference: Affiliate marketing is a structured, paid partnership model with measurable results, while viral marketing is an organic, unpredictable phenomenon driven by audience engagement and social sharing.
- 115 marksOff-page SEO strategiesHideAnswer
Consider you are working as an SEO expert, now explain the possible ways of doing off-page SEO of an e-commerce website. [5]
Off-page SEO refers to optimization techniques performed outside your website to improve its search engine rankings and online visibility. Here are the key ways to implement off-page SEO for an e-commerce website: - Acquire high-quality ...
- 125 marksCollaborative filtering approachesHideAnswer
How can you implement collaborative filtering approaches for recommending products in an e-commerce system?' [5]
Collaborative filtering is a recommendation technique that predicts user preferences based on the assumption that users who agreed in the past will agree in the future. It leverages collective user behavior patterns rather than item cont...