On the Auditability of the Estonian IVXV System and an Attack on Individual Verifiability - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2023

On the Auditability of the Estonian IVXV System and an Attack on Individual Verifiability

Résumé

The development and auditing processes around electronic voting implementations are much too often deficient; this is particularly true for the measures taken to prevent cryptographic errors-potentially with grave consequences for security. To mitigate this, it is common to make the code public in order to allow independent experts to help uncover such flaws. In this paper we present our experiences looking at the IVXV system used for municipal and national elections in Estonia as well as European Parliament elections. It appears that, despite the code being public for over five years, the cryptographic protocol has not seen much scrutiny at the code level. We describe in detail the (lack of) auditability and incentives which have contributed to this situation. We also present a previously unknown vulnerability which contradicts the claimed individual verifiability of the system; this vulnerability should be patched in the next version of IVXV system.

Mots clés

Fichier principal
Vignette du fichier
Estonia_VOTING_23.pdf (270.84 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-04216242 , version 1 (24-09-2023)

Identifiants

Citer

Anggrio Sutopo, Thomas Haines, Peter Rønne. On the Auditability of the Estonian IVXV System and an Attack on Individual Verifiability. Workshop on Advances in Secure Electronic Voting, May 2023, Bol, brac, Croatia. ⟨10.1007/978-3-031-48806-1_2⟩. ⟨hal-04216242⟩
79 Consultations
77 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More