18.04.2013 Views

B2B Integration : A Practical Guide to Collaborative E-commerce

B2B Integration : A Practical Guide to Collaborative E-commerce

B2B Integration : A Practical Guide to Collaborative E-commerce

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

320 <strong>B2B</strong> <strong>Integration</strong> — A <strong>Practical</strong> <strong>Guide</strong> <strong>to</strong> <strong>Collaborative</strong> E-<strong>commerce</strong><br />

Continued from page 319<br />

way. Once a message is sent, non-repudiation capability must be in<br />

place so that there is no question who sent or received a particular<br />

message.<br />

TradeWave secured OASIS transactions by building upon an Entrustbased<br />

Public Key Infrastructure (PKI) <strong>to</strong> create a nonproprietary,<br />

open-architecture solution that meets all relevant industry, government<br />

and international security standards. The standard Entrust PKI was<br />

advanced by 'Web-enabling' it, au<strong>to</strong>mating its ability <strong>to</strong> issue certificates<br />

and adding an access-control <strong>to</strong>ol that handles data-access<br />

privileges for each user.<br />

Security Implementation at MAIN<br />

The major TradeVPI components that support the OASIS architecture<br />

at JTSIN participant MAIN (Mid-America Interconnected Network)<br />

are the TradeWave's online certificate authority (CA) service, client<br />

and server software and the TradeAccess Control Server software.<br />

• A trusted CA direc<strong>to</strong>ry manages and distributes electronic keys for<br />

encrypting information and electronic certificates for authenticating<br />

user and server identities.<br />

• TradeAgent client enables a user's Web browser <strong>to</strong> gain secure<br />

access <strong>to</strong> the Web pages of MAIN and other participating OASIS<br />

utilities.<br />

• TradeAgent Server provides secure MAIN resources, such as<br />

confidential OASIS pages, <strong>to</strong> TradeAgent client users.<br />

• Both the TradeWave client and server software encrypt and decrypt<br />

data detailing the pricing and availability of electricity at MAIN<br />

and other OASIS participants.<br />

• The TradeAccess Control Server software ensures that authenticated<br />

users with the proper access privileges can access certain protected<br />

MAIN and OASIS resources.<br />

User Authentication<br />

Users must first be approved by a local registration agent (LRA), who<br />

provides the user with a security profile. MAIN'S LRA then confirms<br />

Continue on page 321

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!