semper: a security framework for the global electronic marketplca jian zheng [email protected]...

SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng [email protected] Nov. 30, 1998

Upload: todd-york

Post on 18-Dec-2015




0 download


Page 1: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER: A Security Framework for the Global

Electronic Marketplca Jian Zheng

[email protected]

Nov. 30, 1998

Page 2: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• Introduction

• The Security Marketplace

• Model of Electronic Commerce

• SEMPER Architecture

• The Field Trial

• Reference

Page 3: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• IntroductionIntroduction

Page 4: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Introduction• The Emerging Electronic Commerce

– by 2000, over 25B will conducted via Internet

• Such an electronic marketplace requires security and establishing sufficient trust

• Current Achievements:– payment, cryptography, intellectual property rights


– however, they did not integrate the different solution in a consistent way

Page 5: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• SEMPER(Security Electronic Marketplace for Europe) – proposes an open security framework that

should provide an integrated, complete and global electronic marketplace

– backed by the European Commission – technically led by IBM Zurich Research Lab

Page 6: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• The Security MarketplaceThe Security Marketplace

Page 7: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Security Marketplace

• Requirements– The traditional business “terms” and

“requirements” should be appropriately translated into electronic terms

– trust should be restored on such an insecure media (Internet)

– the recovery of transaction and the resolution of dispute must be guaranteed

Page 8: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Security Marketplace(cont’d)• Fundamental Issues

– the systems must address the complete set of issues raised by E-commerce

– users must be able to trust their system– these systems should be fully interoperable– E-commerce needs to be backed by a legal framework

which is transparent and predictable for users– there is a network for registration, certification and key


Page 9: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Security Marketplace(cont’d)

• Current Status– three waves on the Internet business

• web sites for promoting and marketing

• digital libraries and online catalogs

• possible to authenticate, user can browse, place the order and pay for them; secure payment with credit card based on SSL and SET

– however, no generally accepted model and architecture for building E-commerce

Page 10: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Security Marketplace(cont’d)

• SEMPER Objectives– addresses the complete problem of E-commerce

over insecure networks– based on a business model consisting of

“tranfers” and “fair exchanges”– goal: develop an open and comprehensive

security framework for building the secure marketplace

Page 11: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• Model of Electronic CommerceModel of Electronic Commerce

Page 12: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Model for E-commerce

• Model– two-party E-commerce: describes business

scenarios in terms of sequences of “transfers” and “exchanges” of data with decisions based on the success of these actions

– similar to the dialogues of interactive EDI

Page 13: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Model for E-commerce(cont’d)

Page 14: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Model for E-commerce(cont’d)

• Basic Concepts– “transfer”: One party sends a package of

business items to one or more business parties. The sending party specifies the security requirements.

– “exchange”: A simultaneous exchange of packages of business items among two parties.

Page 15: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Model for E-commerce(cont’d)

• Basic Concepts(cont’d)– “business items”:

• credentials

• statements

• money

Page 16: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Model for E-commerce(cont’d)


Money Credential Information

Nothing(i.e., transfer)

Payment Certificatetransfer


Money Air moneyexchange

Fair paymentwith receipt

Fair purchase

Credential Same as … Fair contractsigning


Information … in upper… …right half Fairinformationexchange

Page 17: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• SEMPER ArchitectureSEMPER Architecture

Page 18: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture

• Structured in layers

• the highest layer deals with commercial issues only

• the lowest layer deals with low-level security primitives and other supporting services

Page 19: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

Page 20: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

Page 21: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

• Commerce Service– directly implements protocols of business

scenarios– implements the flow of control– includes some more general use services– can also securely download new services

Page 22: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

• Exchange Service– handle and package business items– transfer and fair exchange of packages– each type of items is managed by a separate

manager which provides the unified services based on integrating existing implementations

• payment manager

Page 23: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

Page 24: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

• Supporting Service– provides user preference management,

persistent object storage, communication, crypto services, access control, etc.

Page 25: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Architecture(cont’d)

• Multi-party security– buyers, service

providers, banks, CA authorities, notary public

• Trust hierarchy– browser/server

– Signed business application

– Commerce layer

– System kernel

Page 26: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

SEMPER Offers Security Services for Today and Tomorrow

• Basic Services– Authentication

– Signed offer

– Signed order

– Payment

– Signed delivery

• Advanced Services– Fair exchange– Security document

handling• certified mail• contract signing• credentials

– New payment instructments

– Anonymity– Resolution of dispute

Page 27: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• the Field Trialthe Field Trial

Page 28: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Field Trial

• EUROCOM– offer multimedia courseware in the area of

telecommunications– implements online purchases of multimedia


Page 29: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Field Trial(cont’d)

• FOGRA– distribute information to their members on a

subscription basis and sell consultancy to non-members

– use SEMPER for online purchase and processing of subscription s well as sales of consultancy

Page 30: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

The Field Trial(cont’d)

• OTTO VERSAND– one of the largest mail-order retailer world wide– online order of goods– online order of tickets and other credentials

Page 31: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• ReferenceReference

Page 32: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998


• SEMPER Home Page–

• SEMPER public reports–

• Security Research Droup at IBM Zurich Research Lab–


Page 33: SEMPER: A Security Framework for the Global Electronic Marketplca Jian Zheng Nov. 30, 1998

Reference(cont’d)• Field Trials

– Actimedia (F) - satellite pictures on ATM networ•

– Acri (F) - CD-ROMs on the Internet•

– Gecap / Bowne (F) - software localisation•

– Viajes Eroski / Enyca (E) - travel•