首页> 外文会议>International conference on e-voting and identity >The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election
【24h】

The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election

机译:新南威尔士州iVote系统:在线实时选举中的安全漏洞和验证漏洞

获取原文

摘要

In the world's largest-ever deployment of online voting, the iVote Internet voting system was trusted for the return of 280,000 ballots in the 2015 state election in New South Wales, Australia. During the election, we performed an independent security analysis of parts of the live iVote system and uncovered severe vulnerabilities that could be leveraged to manipulate votes, violate ballot privacy, and subvert the verification mechanism. These vulnerabilities do not seem to have been detected by the election authorities before we disclosed them, despite a pre-election security review and despite the system having run in a live state election for five days. One vulnerability, the result of including analytics software from an insecure external server, exposed some votes to complete compromise of privacy and integrity. At least one parliamentary seat was decided by a margin much smaller than the number of votes taken while the system was vulnerable. We also found protocol flaws, including vote verification that was itself susceptible to manipulation. This incident underscores the difficulty of conducting secure elections online and carries lessons for voters, election officials, and the e-voting research community.
机译:在全球有史以来最大规模的在线投票部署中,iVote Internet投票系统在2015年澳大利亚新南威尔士州州级选举中获得了280,000票的投票结果,值得信赖。在选举期间,我们对部分实时iVote系统进行了独立的安全分析,并发现了严重的漏洞,可利用这些漏洞来操纵选票,侵犯投票隐私权和颠覆验证机制。尽管在选举前进行了安全审查,并且该系统已在现场直播的选举中运行了五天,但在我们披露这些漏洞之前,选举当局似乎并未发现这些漏洞。一个漏洞是由于包含来自不安全的外部服务器的分析软件而导致的,该漏洞暴露了一些投票权,从而完全破坏了隐私和完整性。至少有一个议会席位是由比该制度脆弱时所通过的选票少得多的票数决定的。我们还发现了协议缺陷,包括本身容易受到操纵的投票验证。此事件凸显了在线进行安全选举的困难,并为选民,选举官员和电子投票研究社区提供了教训。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号