首页> 外文OA文献 >The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election
【2h】

The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election

机译:新南威尔士iVote系统:安全失败和验证   在线直播选举中的缺陷

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In the world's largest-ever deployment of online voting, the iVote Internetvoting system was trusted for the return of 280,000 ballots in the 2015 stateelection in New South Wales, Australia. During the election, we performed anindependent security analysis of parts of the live iVote system and uncoveredsevere vulnerabilities that could be leveraged to manipulate votes, violateballot privacy, and subvert the verification mechanism. These vulnerabilitiesdo not seem to have been detected by the election authorities before wedisclosed them, despite a pre-election security review and despite the systemhaving run in a live state election for five days. One vulnerability, theresult of including analytics software from an insecure external server,exposed some votes to complete compromise of privacy and integrity. At leastone parliamentary seat was decided by a margin much smaller than the number ofvotes taken while the system was vulnerable. We also found protocol flaws,including vote verification that was itself susceptible to manipulation. Thisincident underscores the difficulty of conducting secure elections online andcarries lessons for voters, election officials, and the e-voting researchcommunity.
机译:在全球有史以来最大规模的在线投票部署中,iVote Internetvoting系统在2015年澳大利亚新南威尔士州的州级选举中获得了28万张选票的信任,受到信赖。在选举期间,我们对部分实时iVote系统进行了独立的安全性分析,并发现了严重的漏洞,可利用这些漏洞来操纵选票,破坏选票的隐私权并颠覆验证机制。尽管在选举前进行了安全审查,并且系统已在现场进行了五天的选举,但在我们披露这些漏洞之前,选举当局似乎并未发现这些漏洞。一个漏洞(其中包括来自不安全的外部服务器的分析软件)暴露了一些投票权,以完全破坏隐私和完整性。至少有一个议会席位由比该制度脆弱时所进行的投票数少得多的空白决定。我们还发现了协议缺陷,包括本身容易受到操纵的投票验证。此事件凸显了在网上进行安全的选举以及为选民,选举官员和电子投票研究社区提供课程的困难。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号