DocumentCode
2486839
Title
Distributed e-voting using the Smart Card Web Server
Author
Kyrillidis, Lazaros ; Cobourne, Sheila ; Mayes, Keith ; Dong, Song ; Markantonakis, Konstantinos
Author_Institution
Inf. Security Group, Univ. of London, Egham, UK
fYear
2012
fDate
10-12 Oct. 2012
Firstpage
1
Lastpage
8
Abstract
Voting in elections is the basis of democracy, but citizens may not be able or willing to go to polling stations to vote on election days. Remote e-voting via the Internet provides the convenience of voting on the voter´s own computer or mobile device, but Internet voting systems are vulnerable to many common attacks, affecting the integrity of an election. Distributing the processing of votes over many web servers installed in tamper-resistant, secure environments can improve security: this is possible by using the Smart Card Web Server (SCWS) on a mobile phone Subscriber Identity Module (SIM). This paper proposes a generic model for a voting application installed in the SIM/SCWS, which uses standardised Mobile Network Operator (MNO) management procedures to communicate (via HTTPs) with a voting authority to vote. The generic SCWS voting model is then used with the e-voting system Prêt à Voter. A preliminary security analysis of the proposal is carried out, and further research areas are identified. As the SCWS voting application is used in a distributed processing architecture, e-voting security is enhanced because to compromise an election, an attacker must target many individual mobile devices rather than a centralised web server.
Keywords
Internet; file servers; government data processing; mobile computing; security of data; smart cards; transport protocols; HTTP; Internet voting systems; MNO management procedures; SIM; distributed e-voting; distributed processing architecture; e-voting system Prêt à Voter; election integrity; generic SCWS voting model; mobile network operator management procedures; mobile phone subscriber identity module; remote e-voting; smart card Web server; Cryptography; Electronic voting; Mobile handsets; Nominations and elections; Protocols; Web servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Risk and Security of Internet and Systems (CRiSIS), 2012 7th International Conference on
Conference_Location
Cork
Print_ISBN
978-1-4673-3087-9
Electronic_ISBN
978-1-4673-3088-6
Type
conf
DOI
10.1109/CRISIS.2012.6378952
Filename
6378952
Link To Document