July3,20201Unit11ElectronicCommerceSecurityJuly3,20202Warm-upWordStudyTextAnalysisExercisesJuly3,20203Warm-upThefollowingfiguresarewhatyoucanseewhenyouclicktheVeriSignSecuredSealoneBay.com.Itcanhelpyouidentifythesite.WhatdoyouknowaboutVeriSignandVeriSignSecuredSeal?July3,20204Wordstudyprivacy['praivəsi]n.保密性Inthisplaceprivacyisimpossible.在这种地方保密是不可能的。integrity[in'tegriti]n.完整性Thereisawholerangeofsecuritymeasuresavailabletoensuredataintegrity.有一整套可用安全措施来确保数据完整性。July3,20205Wordstudyauthenticity[ɔ:θen'tisiti]n.真实性Istronglysuspecttheauthenticityofthedocument.我很怀疑该文件的真实性。non-repudiation['nɔŋripju:di'eiʃən]n.不可否认性Non-repudiationisoneoftheimportantquestionsofdevelopmentofelectronicbusinesssystem.不可否认性是开发电子商务系统必须要解决的问题之一。July3,20206Wordstudyencryption[in'kripʃən]n.加密Databaseencryptionisacoresubjectinthefieldofinformationsecurity.数据库加密是信息安全领域研究的一个核心课题。algorithm['ælgəriðəm]n.算法Letusstartwithanimmediateconsequenceofthealgorithm.我们先提出该算法的一个直接推论。July3,20207Wordstudysymmetrical[si'metrikəl]adj.对称的Heintroducedtousthesymmetricalarrangementofthegarden.他为我们介绍了花园对称的布局。encrypt[in'kript]vt.加密Theconnectionattemptfailedbecauseofthefailuretoencryptdata.错误的加密数据造成连接请求失败。July3,20208Wordstudydecrypt[di:'kript]vt.解密Thespecifiedfileisencryptedandtheuserdoesnothavetheabilitytodecryptit.指定的文件已加密,而且用户没有能力解密。asymmetrical[æsi'metrikl]adj.不对称的Mostpeople'sfacesareasymmetrical.大多数人的脸是不对称的。July3,20209WordstudyHashing['hæʃiŋ]n.散列法,哈希算法ThesystemisnotabletoverifythissignaturebecauseitdoesnotsupporttheHashingalgorithm.系统无法验证此签名,因为它不支持哈希算法。identity[ai'dentiti]n.身份Acreditcardisnotavalidproofofidentity.信用卡不是有效的身份证明。July3,202010Wordstudyauthentication[ɔ:θenti'keiʃən]n.证明,鉴定Identificationauthenticationserverprovidespasswordauthenticationanddigitalcertificateauthentication.身份认证服务器提供口令认证和数字证书认证两种方式。trustworthiness[trʌst'wə:ðinis]n.可信任Iqueryhistrustworthiness.我对他的可靠性有怀疑。July3,202011Wordstudyidentification[aidentifi'keiʃən]n.身份证明Iusedmydriver'slicenseasidentification.我用驾驶执照作为身份证明。unilateral['ju:ni'lætərəl]adj.单方的Theytaketheunilateraldecisiontocancelthecontract.他们单方面决定撤消合同。July3,202012Wordstudyrepudiation[ripju:di'eiʃən]n.否认Hisrepudiationofthetransactionwasunacceptable.他对交易的否认令人无法接受。vulnerable['vʌlnərəb(ə)l]adj.易受攻击的Thepotatoisvulnerabletoseveralpests.马铃薯易受几种害虫的侵害。incredible[in'kredəbl]adj.难以置信的That'sthemostincrediblecoincidenceI'veeverheardof!那是我听说过的最难以置信的巧合!July3,202013TextAnalysisRequirementsforElectronicCommerceSecurityIngeneral,thebasicrequirementsforelectroniccommercesecurityincludeprivacy,integrity,authenticityandnon-repudiation.July3,202014TextAnalysisPrivacyWhenamessageissentelectronically,thesenderandthereceivermaydesirethatthemessageisnotrevealedtoothers.Themosteffectivetechniqueforprivacyisencryption.Formuchofhistory,encryptionalgorithmsweresymmetrical,whichmeansthatthesamekeywasusedtobothencryptanddecryptamessage.Thedifficultyishowtohavethesenderandthereceiverwhowillprobablynevermeetagreeonakeythatcannotbeknownbyanyoneelse.(译文)July3,202015TextAnalysisForthisreason,anewtypeofalgorithm,calledpublickeyencryption,wasinvented.Publickeyencryption,alsoknownasasymmetricalencryption,utilizesapairofkeys—publickeyandprivatekey.Thepublickeyisavailabletoanyonewhowantstosendanencryptedmessagetotheholderoftheprivatekey.(译文)Theonlywaytodecryptthemessageiswiththeprivatekey.Inthiswaymessagescanbesentwithoutagreeingonthekeysinadvance.July3,202016TextAnalysisIntegrityAmessagethathasnotbeenalteredinanyway,eitherintentionallyorunintentionally,issaidtohavemaintaineditsintegrity.(译文)Aneffectivewaycalled“Hashing”canbeusedtoensuremessageintegrity.TheHashvalueofamessageiscomputedusingHashingalgorithmandcontentofthemessage.July3,202017TextAnalysisTheHashvalueissentalongwiththemessage,whenmessageisreceived,anotherHashvalueiscalculatedbythereceiverusingthesameHashingalgorithm.(译文)ThetwoHashvalues(receivedandcalculated)arecomparedandamatchwillindicatethatthemessagereceivedisthesameasthesentone.(译文)July3,202018TextAnalysisAuthenticityWhenanelectronicmessageisreceived,theidentityofthesenderneedstobeverifiedinordertodeterminewhetherthesenderiswhoheclaimstobe.(译文)Oneofthemosteffectiveauthenticationmeasuresisdigitalcertificate.AdigitalcertificateisadatafileandisissuedbyatrustedthirdpartycalledCA.Thereareanumberoftypesofdigitalcertificates,eachwithitsownleveloftrustworthinessandareaofapplication.(译文)Ingeneral,adigitalcertificateincludes:July3,202019TextAnalysisthenameoftheholderandotheridentificationinformation.theholder’spublickeywhichcanbeusedtoencryptmessage.thenameoftheCAthatissuedthedigitalcertificate.thevalidityperiodofthedigitalcertificate.July3,202020TextAnalysisNon-repudiationForbusinesstransactions,unilateralrepudiationofatransactionbyeitherpartyisunacceptableandmayresultinlegalaction.(译文)Companiesengagedinelectroniccommerceareoftenvulnerabletonon-repudiationrisks.Aneffectivewaytoenablenon-repudiationisdigitalsignature.Adigitalsignatureisactuallyadigestofmessagethatisencryptedandthensentalongwiththemessage.Whenyouuseaprivatekeytoencryptadigestofmessage,youcreateadi