• DocumentCode
    2486839
  • Title

    Distributed e-voting using the Smart Card Web Server

  • Author

    Kyrillidis, Lazaros ; Cobourne, Sheila ; Mayes, Keith ; Dong, Song ; Markantonakis, Konstantinos

  • Author_Institution
    Inf. Security Group, Univ. of London, Egham, UK
  • fYear
    2012
  • fDate
    10-12 Oct. 2012
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Voting in elections is the basis of democracy, but citizens may not be able or willing to go to polling stations to vote on election days. Remote e-voting via the Internet provides the convenience of voting on the voter´s own computer or mobile device, but Internet voting systems are vulnerable to many common attacks, affecting the integrity of an election. Distributing the processing of votes over many web servers installed in tamper-resistant, secure environments can improve security: this is possible by using the Smart Card Web Server (SCWS) on a mobile phone Subscriber Identity Module (SIM). This paper proposes a generic model for a voting application installed in the SIM/SCWS, which uses standardised Mobile Network Operator (MNO) management procedures to communicate (via HTTPs) with a voting authority to vote. The generic SCWS voting model is then used with the e-voting system Prêt à Voter. A preliminary security analysis of the proposal is carried out, and further research areas are identified. As the SCWS voting application is used in a distributed processing architecture, e-voting security is enhanced because to compromise an election, an attacker must target many individual mobile devices rather than a centralised web server.
  • Keywords
    Internet; file servers; government data processing; mobile computing; security of data; smart cards; transport protocols; HTTP; Internet voting systems; MNO management procedures; SIM; distributed e-voting; distributed processing architecture; e-voting system Prêt à Voter; election integrity; generic SCWS voting model; mobile network operator management procedures; mobile phone subscriber identity module; remote e-voting; smart card Web server; Cryptography; Electronic voting; Mobile handsets; Nominations and elections; Protocols; Web servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risk and Security of Internet and Systems (CRiSIS), 2012 7th International Conference on
  • Conference_Location
    Cork
  • Print_ISBN
    978-1-4673-3087-9
  • Electronic_ISBN
    978-1-4673-3088-6
  • Type

    conf

  • DOI
    10.1109/CRISIS.2012.6378952
  • Filename
    6378952