Electronic Cash
Electronic Cash
Electronic Cash
11-1
At a Glance
11-2
Lecture Notes
Chapter Overview
An important function of electronic commerce sites is the handling of payments over the Internet. Most electronic commerce involves the exchange of some form of money for goods or services. As you learned in Chapter 5, many companies use electronic funds transfers (EFTs) or financial EDI to make online payments. In this chapter, you will learn about a number of online payment alternatives that are available to individual consumers.
Chapter Objectives
In this chapter, you will learn about: The basic functions of online payment systems The use of payment cards in electronic commerce The history and future of electronic cash How electronic wallets work The use of stored-value cards in electronic commerce Internet technologies and the banking industry
Instructor Notes
Online Payment Basics
Today, four basic ways to pay for purchases dominate both traditional and electronic business-to-consumer commerce. Cash, checks, credit cards, and debit cards account for more than 90 percent of all consumer payments in the United States. A small but growing percentage of consumer payments are made by electronic transfer. The most popular consumer electronic transfers are automated payments of auto loans, insurance payments, and mortgage payments made from consumers checking accounts. Credit cards are by far the most popular form of consumer electronic payments online. Recent surveys have found that more than 85 percent of worldwide consumer Internet purchases are paid for with credit cards. In the United States, the proportion is about 96 percent. Another payment medium is limited-use scrip. Scrip is digital cash minted by a company instead of by a government. Most scrip cannot be exchanged for cash; it must be exchanged for goods or services by the company that issued the scrip. Scrip is like a gift certificate that is good at more than one store. In the early days of the Web, many experts predicted that scrip would become a popular way of making payments for consumer goods and services online. Unfortunately for many investors and at least two companies, this turned out not to be true.
11-3
Payment Cards
Businesspeople often use the term payment card as a general term to describe all types of plastic cards that consumers (and some businesses) use to make purchases. The main categories of payment cards are credit cards, debit cards, and charge cards.
Payment Cards:
Credit card: Has a spending limit based on the users credit history; a user can pay off the entire credit card balance or pay a minimum amount each billing period. Debit card: Removes the amount of the sale from the cardholders bank account and transfers it to the sellers bank account. Charge card: Carries no spending limit, and the entire amount charged to the card is due at the end of the billing period.
11-4
for the handling of payment card transactions called the EMV standard (EMV is derived from the names of the companies: Europay, MasterCard, and Visa).
The merchant authenticates the payment card to ensure it is valid and not stolen. The merchant checks with the payment card issuer to ensure that credit or funds are available and puts a hold on the credit line or the funds needed to cover the charge. Settlement occurs, usually a few days after the purchase, which means that funds travel between banks and are placed into the merchants account.
Quick Quiz
1. _____ is a general term that describes any value storage and exchange system created by a private (nongovernmental) entity that does not use paper documents or coins and that can serve as a substitute for government-issued physical currency. Answer: Electronic cash Internet payments for items costing from a few cents to approximately a dollar are called _____. Answer: micropayments _____ is spending a particular piece of electronic cash twice by submitting the same electronic currency to two different vendors. Answer: Double spending _____ is a technique used by criminals to convert money that they have obtained illegally into cash that they can spend without having it identified as the proceeds of an illegal activity. Answer: Money laundering
2. 3.
4.
Electronic Cash
Although credit cards dominate online payments today, electronic cash shows promise for the future. Gartner, Inc. estimates that electronic cash will be used in more than 60 percent of all online transactions by 2009. Electronic cash (also called e-cash or digital cash) is a general term that describes any value storage and exchange system created by a private (nongovernmental) entity that does not use paper documents or coins and that can serve as a substitute for government-issued physical currency. A significant difference between electronic cash and scrip is that electronic cash can be readily exchanged for physical cash on demand. Because electronic cash is issued by private entities, there is a need for common standards among all electronic cash issuers so that one issuers electronic cash can be accepted by another issuer. This need has not yet been met. Each issuer has its own standards and electronic cash is not universally accepted, as is government-issued physical currency.
Teaching
Have students research Web sites that accept electronic cash and determine the type of organizations that accept this form of payment. Students should submit a brief report
11-5
Electronic Cash:
Micropayments and Small Payments: Internet payments for items costing from a few cents to approximately a dollar are called micropayments. Micropayment champions see many applications for such small transactions, such as paying 5 cents for an article reprint or 25 cents for a complicated literature search. However, micropayments have not been implemented very well on the Web yet. Privacy and Security of Electronic Cash: Electronic cash should have two important characteristics in common with physical currency. First, it must be possible to spend electronic cash only once, just as with traditional currency. Second, electronic cash ought to be anonymous, just as hard currency is. Holding Electronic Cash: Online and Offline Cash: Online cash storage means that the consumer does not personally possess electronic cash. Instead, a trusted third party (an online bank) is involved in all transfers of electronic cash and holds the consumers cash accounts. Offline cash storage is the virtual equivalent of money kept in a wallet. The customer holds it, and no third party is involved in the transaction. Protection against fraud is still a concern, so either hardware or software safeguards must be used to prevent fraudulent or double-spending.
11-6
Cryptographic algorithms are the keys to creating tamper-proof electronic cash that can be traced back to its origins. A two-part lock provides anonymous security that also signals when someone is attempting to double-spend cash. When a second transaction occurs for the same electronic cash, a complicated process comes into play that reveals the identity of the original electronic cash holder. Otherwise, electronic cash that is used correctly maintains a users anonymity. This double-lock procedure protects the anonymity of electronic cash users and simultaneously provides built-in safeguards to prevent double-spending.
11-7
Double-spending can neither be detected nor prevented with truly anonymous electronic cash. Anonymous electronic cash is electronic cash that, like bills and coins, cannot be traced back to the person who spent it. One way to be able to trace electronic cash is to attach a serial number to each electronic cash transaction. That way, cash can be positively associated with a particular consumer. That does not solve the double-spending problem, however. Although a single issuing bank could detect if two deposits of the same electronic cash are about to occur, it is impossible to ascertain who is at fault in such a situation - the consumer or the merchant. Of course, electronic cash that contains serial numbers is no longer anonymous, and anonymity is one reason to acquire electronic cash in the first place. Electronic cash containing serial numbers also raises a number of privacy issues, because merchants could use the serial numbers to track spending habits of consumers.
CheckFree: The largest online bill processor in the world, provides online payment processing services to both large corporations and individual Internet users. Clickshare: An electronic cash system aimed at magazine and newspaper publishers. InternetCash: Provides electronic currency that is very similar to traditional cash. Similar to prepaid phone cards, the InternetCash cards come in denominations of $10, $20, $50, and $100. PayPal: Provides payment processing services to businesses and to individuals. PayPal earns a profit on the float, which is money that is deposited in PayPal accounts and not used immediately.
Quick Quiz
1. 2. 3. Internet payments for items costing from a few cents to approximately a dollar are called _____. Answer: micropayments True or False: Online cash storage is the virtual equivalent of money kept in a wallet. Answer: False _____ is a technique used by criminals to convert money that they have obtained illegally into cash that they can spend without having it identified as the proceeds of an illegal activity. Answer: Money laundering _____ is electronic cash that, like bills and coins, cannot be traced back to the person who spent it. Answer: Anonymous electronic cash
4.
11-8
Electronic Wallets
As consumers are becoming more enthusiastic about online shopping, they have begun to tire of repeatedly entering detailed shipping and payment information each time they make online purchases. Filling out forms ranks high on online customers list of gripes about online shopping. To address these concerns, many electronic commerce sites include a feature that allows a customer to store name, address, and credit card information on the site. However, consumers must enter their information at each site with which they want to do business. An electronic wallet (sometimes called an e-wallet), serving a function similar to a physical wallet, holds credit card numbers, electronic cash, owner identification, and owner contact information and provides that information at an electronic commerce sites checkout counter. Electronic wallets give consumers the benefit of entering their information just once, instead of having to enter their information at every site with which they want to do business. Electronic wallets fall into two categories based on where they are stored. A server-side electronic wallet stores a customers information on a remote server belonging to a particular merchant or wallet publisher. The main weakness of serverside electronic wallets is that a security breach could reveal thousands of users personal information - including credit card numbers - to unauthorized parties. Typically, server-side electronic wallets employ strong security measures that minimize the possibility of unauthorized disclosure. A client-side electronic wallet stores a consumers information on his or her own computer. Many of the early electronic wallets were client-side wallets that required users to download the wallet software. This need to download software onto every computer used to make purchases is a chief disadvantage of client-side wallets. Server-side wallets, on the other hand, remain on a server and thus require no download time or installation on a users computer. Before a consumer can use a server-side wallet on a particular merchants site, the merchant must enable that specific wallet. Each wallet vendor must convince a large number of merchants to enable its wallet before it will be accepted by consumers. Thus, only a few server-side wallet vendors will be able to succeed in the market.
Teaching
Have students conduct research on the Web to determine the security implications of using an e-wallet.
11-9
Stored-Value Cards
Today, most people carry a number of plastic cards - credit cards, debit cards, charge cards, drivers license, health insurance card, employee or student identification card, and others. One solution that could reduce all those cards to a single plastic card is called a stored-value card. A stored-value card can be an elaborate smart card with a microchip or a plastic card with a magnetic strip that records the currency balance. The main difference is that a smart card can store larger amounts of information and includes a processor chip on the card. The card readers needed for smart cards are different, too. Common storedvalue cards include prepaid phone, copy, subway, and bus cards.
Stored-Value
Magnetic strip card: Holds a value that can be recharged by inserting it into the appropriate machines, inserting currency into the machine, and withdrawing the card; the cards strip stores the increased cash value. Magnetic strip cards are passive; that is, they cannot send or receive information, nor can they increment or decrement the value of cash stored on the card. Smart card: A stored-value card that is a plastic card with an embedded microchip that can store information. Credit, debit, and charge cards currently store limited information on a magnetic strip. A smart card can store about 100 times the amount of information that a magnetic strip plastic card can store. A smart card can hold private user data, such as financial facts, encryption keys, account information, credit card numbers, health insurance information, medical records, and so on.
11-10
Source: http://www.fcw.com/fcw/articles/2004/0419/web-nist-04-23-04.asp Question 1. 2. What are the advantages of developing technical standards? Why do you think smart cards have not been as successful in the United States as they have been in Europe?
11-11
The basic structure of a phishing attack is fairly simple. The attacker sends e-mail messages to a large number of recipients who might have an account at the targeted Web site. The e-mail message tells the recipient that his or her account has been compromised and it is necessary for the recipient to log in to the account to correct the matter. The e-mail message includes a link that appears to be a link to the login page of the Web site. However, the link actually leads the recipient to the phishing attack perpetrators Web site, which is disguised to look like the targeted Web site. The unsuspecting recipient enters his or her login name and password, which the perpetrator captures and then uses to access the recipients account. Once inside the victims account, the perpetrator can access personal information, make purchases, or withdraw funds at will.
Quick Quiz
1. A(n) _____ wallet stores a customers information on a remote server belonging to a particular merchant or wallet publisher. Answer: server-side electronic True or False: The ECML standard will expedite online processing for customers by simplifying the formfilling procedure. Answer: True A(n) _____ can be an elaborate smart card with a microchip or a plastic card with a magnetic strip that records the currency balance. Answer: stored-value card True or False: Smart cards are safer than conventional credit cards because the information stored on a smart card is encrypted. Answer: True
2.
3.
4.
Discussion Questions
Why is the idea of using electronic cash still so popular despite the many failures in the last few years? Why do you think micropayments have so far, not been implemented very well on the Web?
Key Terms
Acquiring bank: Bank that does business with sellers (both Internet and non-Internet) that want to accept
payment cards.
Chargeback: The process that occurs when a cardholder successfully contests a charge and the merchant bank
retrieves the money it placed in the merchant account. Double-spending: Spending a particular piece of electronic cash twice by submitting the same electronic currency to two different vendors. Electronic cash: A general term that describes any value storage and exchange system created by a private (nongovernmental) entity that does not use paper documents or coins and that can serve as a substitute for government-issued physical currency. Micropayments: Internet payments for items costing from a few cents to approximately a dollar. Money laundering: A technique used by criminals to convert money that they have obtained illegally into cash that they can spend without having it identified as the proceeds of an illegal activity.
11-12
Smart card: A stored-value card that is a plastic card with an embedded microchip that can store information.