Title :
A novel mechanism for secure e-tendering in an open electronic network
Author :
Damsika, Ameera ; Ranasinghe, Dulhan ; Kulkarni, Devdatta
Author_Institution :
Sch. of Comput., Asia Pacific Inst. of Inf. Technol. - Sri Lanka, Colombo, Sri Lanka
Abstract :
It is considered a good practice when traditional paper-based business documents and processes are migrated to digital systems. As evident from the past 3-4 decades of digital revolution, using available or new digital technology has plenty of advantages in achieving business objectives. Electronic Tendering (e-tendering), is one such application through which calls, proposals, bids and reviews are exchanged between interested parties for securing a project that is published via a tender management system. Few e-tendering systems exist that automate all the processes. Although, techniques have been developed to provide the basic exchange of documents and messaging service, very little research and application has been done in the area of authentication, secure exchange of data, and storage of tender applications in multi-user environments. Our work focuses on developing a holistic solution for meeting the security requirements of e-tendering system. We first investigate the main drawbacks of using SSL for such applications, and also highlight the threats, attacks and implementation issues encountered in implementing systems without SSL. In this paper we propose a novel mechanism to overcome the drawbacks, focusing on the e-tendering steps related to authentication, submission of bid proposal, data transmission and key exchange between trusted parties, and secure data storage. In each of these steps, we identify the possible attacks and propose novel ways to apply techniques so that the security needs are met. We believe that our application of techniques, use of key exchange in e-tendering, and other algorithms provides a practical mechanism for secure e-tendering in open electronic networks. The prototype we have developed shows that our framework is very usable, and could easily be adapted as a secure e-trading system in practice.
Keywords :
authorisation; business data processing; cryptography; document handling; electronic data interchange; trusted computing; SSL; authentication; bid proposal submission; business objectives; data transmission; digital systems; document exchange; electronic tendering; key exchange; messaging service; open electronic network; paper-based business documents; secure data exchange; secure data storage; secure e-tendering; secure e-trading system; tender management system; trusted parties; Computers; Encryption; Service-oriented architecture; Streaming media; Cryptography; Session key; Steganography;
Conference_Titel :
Computer Science & Education (ICCSE), 2013 8th International Conference on
Conference_Location :
Colombo
Print_ISBN :
978-1-4673-4464-7
DOI :
10.1109/ICCSE.2013.6553970