Skip to main content

Practical Security Analysis of E-Voting Systems

  • Conference paper
Book cover Advances in Information and Computer Security (IWSEC 2007)

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 4752))

Included in the following conference series:

Abstract

We adapt game theoretic methods for studying the security of two e-voting systems: the Estonian E-Voting System (EstEVS) and Secure Electronic Registration and Voting Experiment (SERVE) performed in the United States of America. While these two systems are quite similar from technical side, security experts have made totally different decisions about their security—EstEVS was indeed used in practical elections while SERVE was decided to be insecure. The aim of this work is to clarify if the minor technical differences between these two systems were indeed a sufficient reason to distinguish between their security. Our analysis is oriented to practical security against large-scale attacks. We define a model for the real-life environment in which voting takes place and analyze the behavior of adversaries. We show that in our model EstEVS is secure and SERVE is not. The reliability of the results is still questionable because of our limited knowledge about many of the parameters. It turns out though that our main results are quite robust with respect to the choice of parameters.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Jefferson, D., Rubin, A.D., Simons, B., Wagner, D.: A Security Analysis of the Secure Electronic Registration and Voting Experiment (SERVE) (2004)

    Google Scholar 

  2. Ansper, A., Buldas, A., Oruaas, M., Priisalu, J., Veldre, A., Willemson, J., Kivinurm, K.: The Security of Conception of E-voting: Analysis and Measures. E-hääletamise kontseptsiooni turve: analüüs ja meetmed (2003)

    Google Scholar 

  3. Buldas, A., Laud, P., Priisalu, J., Saarepera, M., Willemson, J.: Rational Choice of Security Measures via Multi-Parameter Attack Trees. In: Lopez, J. (ed.) CRITIS 2006. LNCS, vol. 4347, pp. 235–248. Springer, Heidelberg (2006)

    Google Scholar 

  4. Estonian National Electoral Committee home page, http://www.vvk.ee

  5. Schneier, B.: Attack Trees. Dr. Dobb’s Journal, Modeling Security Threats (December 1999)

    Google Scholar 

  6. Geer, D., Hoo, K.S., Jaquith, A.: Information Security: Why the Future Belongs to the Quants? IEEE Security and Privacy, 32–40 (July/August 2003)

    Google Scholar 

  7. Interview with Estonian public prosecutor Mr. Margus Kurm

    Google Scholar 

  8. Surf, M., Shulman, A.: How safe is it out there? Zeroing in on the vulnerabilities of application security. Imperva Application Defense Center (2004)

    Google Scholar 

  9. The elections’ atlas of the USA, http://www.uselectionatlas.org/

  10. The Parlimental Elections in Estonia (2003), http://www.vvk.ee/r03/yld_kulud.stm

  11. Department of Defense Washington Headquarters Services Federal Voting assistance Program. Voting Over the Internet Pilot Project Assessment Report (2001)

    Google Scholar 

  12. E-voting System: Overview. Estonian National Electoral Committee (2005), http://www.vvk.ee/elektr/docs/Yldkirjeldus-eng.pdf

  13. Triinu Mägi. Practical Security Analysis of E-voting Systems. Msc Thesis. Tallinn University of Technology (2007), http://triinu.net/pro/

Download references

Author information

Authors and Affiliations

Authors

Editor information

Atsuko Miyaji Hiroaki Kikuchi Kai Rannenberg

Rights and permissions

Reprints and permissions

Copyright information

© 2007 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Buldas, A., Mägi, T. (2007). Practical Security Analysis of E-Voting Systems. In: Miyaji, A., Kikuchi, H., Rannenberg, K. (eds) Advances in Information and Computer Security. IWSEC 2007. Lecture Notes in Computer Science, vol 4752. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-75651-4_22

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-75651-4_22

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-75650-7

  • Online ISBN: 978-3-540-75651-4

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics