Paper 2008/157

Secure Online Elections in Practice

Lucie Langer, Axel Schmidt, and Johannes Buchmann

Abstract

Current remote e-voting schemes aim at a number of security objectives. However, this is not enough for providing secure online elections in practice. Beyond a secure e-voting protocol, there are many organizational and technical security requirements that have to be satisfied by the operational environment in which the scheme is implemented. We have investigated four state-of-the-art e-voting protocols in order to identify the organizational and technical requirements which these protocols need to be met in order to work correctly. Satisfying these requirements is a costly task which reduces the potential advantages of e-voting considerably. We introduce the concept of a Voting Service Provider (VSP) which carries out electronic elections as a trusted third party and is responsible for satisfying the organizational and technical requirements. We show which measures the VSP takes to meet these requirements. To establish trust in the VSP we propose a Common Criteria evaluation and a legal framework. Following this approach, we show that the VSP enables secure, cost-effective, and thus feasible online elections.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. not published elsewhere
Keywords
E-VotingE-GovernmentVoting Service ProviderCertification Authority
Contact author(s)
langer @ cdc informatik tu-darmstadt de
History
2008-04-09: received
Short URL
https://ia.cr/2008/157
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2008/157,
      author = {Lucie Langer and Axel Schmidt and Johannes Buchmann},
      title = {Secure Online Elections in Practice},
      howpublished = {Cryptology ePrint Archive, Paper 2008/157},
      year = {2008},
      note = {\url{https://eprint.iacr.org/2008/157}},
      url = {https://eprint.iacr.org/2008/157}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.