Re: Where this fits in
Tom Arnold <[email protected]> Wed, 26 May 1999 22:26:25 -0700
| Newsgroups | gmane.ietf.scmp |
|---|---|
| Message-ID | <[email protected]> |
Yes. There are several. Of the ones listed, I'm most familiar with the Rosetta, OBI, and IOTP. I'm going to take a look at Internet EDI and respond back to the list with that one... First off: SCMP was designed to be a "request and reply" protocol. In essence, a single message is sent from a sender to a server. Given the assumption that the sender and receiver have previously established a trusted relationship, the receiver of the SCMP request authenticates the message, examines the payload, performs the functions requeste, formats a reply, and sends the reply back to the request. Second: There is no description of payload, requirements on the server for payload handling, implications on business processing, or requirements for the server to hold state. In several of the other protocols, there are fields described, there a functions and processes that must be performed on the fields, and there are implied trading relationships. Let me state that these are all necessary things, but they involve how a business might be run and require some agreement between both trading partners. Our view of the world is that SCMP could be used to move many of these messages around. For instance, it would be perfectly reasonable for two entities to agree to use ANSI-X12/EDI. In this case, the "SCMP-message-type:" might be set to "ANSI-X12/EDI/Ver5036/Doc850" or something. The receiver of this message would know to hand the payload off to the EDI translater and respond with some form of acknowledgement message.... (this is an over simplification as the application doing the payload processing would have to do a bit more, but I think you get the drift). Our plan in this area was to have people thinking of SCMP as a general method for moving commerce messages. The next step is to follow this up with an Informational document that describes specific payloads related to the other protocols. Does this help position what SCMP is? At 03:38 PM 5/25/99 -0500, Bill Brice wrote: >There seem to be several internet e-commerce trading protocols >being developed: > >Internet EDI >IOTP (Internet Open Trading Protocol) >XML DTD's (Rosetta, BizTalk, CommerceNet, etc.) > >Where does SCMP fit in? What other protocols is it most like, >most unlike? What does it do that the others do not? Thanks. > >-Bill Brice, CEO >AlphaTrust.com > >-----Original Message----- >From: Rik Drummond [mailto:[email protected]] >Sent: Tuesday, May 25, 1999 8:07 PM >To: Jason Eaton; [email protected] >Cc: [email protected] >Subject: RE: Welcome! - Current SCMP Draft Issues, Opening Discussion > > >Have you looked at the ediint stuff? how does this differ? I have read part >of the spec.... best regards, rik > >-----Original Message----- >From: [email protected] [mailto:[email protected]]On Behalf >Of Jason Eaton >Sent: Tuesday, May 25, 1999 2:56 PM >To: >Cc: [email protected] >Subject: Welcome! - Current SCMP Draft Issues, Opening Discussion > > > >Welcome to the SCMP discussion email list! Thanks to Paul Hoffman and IMC >for hosting the list. > >This email list is for the discussion of the SCMP ( Simple Commerce >Messaging Protocol ). SCMP is a proposed standard for the exchange of >e-commerce messages over the internet. > >The current draft can be found at, >http://search.ietf.org/internet-drafts/draft-arnold-scmp-02.txt > >SCMP Background > > SCMP was developed by engineers at the CyberSource corporation when a >need for a secure, real-time messaging protocol was identified. SCMP was >first used as a protocol for e-commerce transactions in March of 1997. >Since then the protocol has been modified many times. The S/MIME v2 >informational RFC was incorporated into SCMP in May of 98. > > SCMP was developed to address e-commerce needs of message privacy, >authentication, authorization, accounting, and non-repudiation. In the >e-commerce world where financial transactions are made on behalf of trading >partners, usually the merchant and consumer, these protocol features are >required and have tangible consequences if not supported. > > Currently SCMP is the protocol used here at CyberSource to securely >communicate with over 300 internet merchants sending approximately 2 >million transactions per month. > >Draft Status > > The SCMP draft has been accepted by the Applications area of the IETF. >The Application area directors are Patrik Faltstrom and Keith Moore. The >applications is suitable as SCMP is an application of S/MIME. > > The are several areas in the current draft that need clarification and/or >elaboration. I have made significant changes to the draft since the draft >was submitted to the IETF. I will post a follow up message stating these >changes and possibly the content of the latest draft. > >The authors want to thank everybody in advance for contributing to the >draft. > >Welcome and let the discussion begin! > > >Jason Eaton CyberSource Corporation >Phone 408.260.6044 Security Engineering Manager >[email protected] http://www.cybersource.com > > Thomas A. Arnold Vice President of Engineering Chief Technical Officer CyberSource Corporation [email protected] http://www.cybersource.com/ ---------------------------------------------------- This Email and any attached files are confidential and may also be privileged. <bold><italic> </italic></bold>It is intended only for the individual or entity to whom it is addressed. If you are not the recipient or an authorized agent of the recipient, you are hereby notified that any use, dissemination, distribution or copying of this communication is strictly prohibited. If you have received this message in error, please contact CyberSource Corporation immediately at (408) 556-9100. Thank you.