Estonian Voting Verification Mechanism Revisited

نویسندگان

  • Koksal Mus
  • Mehmet Sabir Kiraz
  • Murat Cenk
  • Isa Sertkaya
چکیده

After the Estonian Parliamentary Elections held in 2011, an additional verification mechanism was integrated into the i-voting system in order to resist corrupted voting devices, including the so called Student’s Attack where a student practically showed that the voting system is indeed not verifiable by developing several versions of malware capable of blocking or even changing the vote. This mechanism gives voters the opportunity to verify whether the vote they cast is stored in the central system correctly. However, the verification phase ends by displaying the cast vote in plain form on the verification device. In other words, the device on which the verification is done learns the voter’s choice. In this work, our aim is to investigate this verification phase in detail and to point out that leaking the voter’s choice to the verification application may harm the voter privacy. Additionally, when applied in a wide range, this would even compromise the fairness and the overall secrecy of the elections. In this respect, we propose an alternative verification mechanism for the Estonian i-voting system to overcome this vulnerability. Not only is the proposed mechanism secure and resistant against corrupted verification devices, so does it successfully verify whether the vote is correctly stored in the system. We also highlight that our proposed mechanism brings only symmetric encryptions and hash functions on the verification device, thereby mitigating these weaknesses in an efficient way with a negligible cost. More concretely, it brings only m additional symmetric key decryptions to the verification device, where m denoting the number of candidates. Finally, we prove the security of the proposed verification mechanism and compare the cost complexity of the proposed method with that of the current mechanism.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Estonian Voting Verification Mechanism Revisited Again

Recently, Muş, Kiraz, Cenk and Sertkaya proposed an improvement over the present Estonian Internet voting vote verification scheme [6, 7]. This paper points to the weaknesses and questionable design choices of the new scheme. We show that the scheme does not fix the vote privacy issue it claims to. It also introduces a way for a malicious voting application to manipulate the vote without being ...

متن کامل

Homomorphic Tallying for the Estonian Internet Voting System

In this paper we study the feasibility of using homomorphic tallying in the Estonian Internet voting system. The paper analyzes the security benefits provided by homomorphic tallying, the costs introduced and the required changes to the voting system. We find that homomorphic tallying has several security benefits, such as improved ballot secrecy, public verifiability of the vote tallying serve...

متن کامل

Log Analysis of Estonian Internet Voting 2013-2014

This paper presents analysis of Internet voting system logs of 2013 local municipal and 2014 European Parliament elections in Estonia. We study both sociodemographic characteristics of voters and technical aspects of voting. Special attention is paid to voting and verification sessions that can be considered irregular (e.g. inability to cast a valid vote or failed verifications). We observe sev...

متن کامل

E-voting in Estonia 2005. The first Practice of Country-wide binding Internet Voting in the World

At Estonian local elections in October 2005 for the first time in the world binding country-wide remote Internet voting took place: whole Estonian electorate had a possibility to cast the vote via Internet. Approximately 2 % of actual voters made use of this possibility. The e-voting surveys show that the attitude of the Estonian public toward e-voting was and is positive; gender, income, educa...

متن کامل

Electronic Voting 2006

At Estonian local elections in October 2005 for the first time in the world binding country-wide remote Internet voting took place: whole Estonian electorate had a possibility to cast the vote via Internet. Approximately 2 % of actual voters made use of this possibility. The e-voting surveys show that the attitude of the Estonian public toward e-voting was and is positive; gender, income, educa...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1612.00668  شماره 

صفحات  -

تاریخ انتشار 2016