Electronic Voting: Methods and Protocols Christopher Andrew Collord James Madison University
Total Page:16
File Type:pdf, Size:1020Kb
James Madison University JMU Scholarly Commons Masters Theses The Graduate School Spring 2013 Electronic voting: Methods and protocols Christopher Andrew Collord James Madison University Follow this and additional works at: https://commons.lib.jmu.edu/master201019 Part of the Computer Sciences Commons Recommended Citation Collord, Christopher Andrew, "Electronic voting: Methods and protocols" (2013). Masters Theses. 177. https://commons.lib.jmu.edu/master201019/177 This Thesis is brought to you for free and open access by the The Graduate School at JMU Scholarly Commons. It has been accepted for inclusion in Masters Theses by an authorized administrator of JMU Scholarly Commons. For more information, please contact [email protected]. Electronic Voting: Methods and Protocols Christopher A. Collord A thesis submitted to the Graduate Faculty of JAMES MADISON UNIVERSITY In Partial Fulfillment of the Requirements for the degree of Master of Science InfoSec 2009 Cohort May 2013 Dedicated to my parents, Ross and Jane, my wife Krista, and my faithful companions Osa & Chestnut. ii Acknowledgements: I would like to acknowledge Krista Black, who has always encouraged me to get back on my feet when I was swept off them, and my parents who have always been there for me. I would also like to thank my dog, Osa, for sitting by my side for countless nights and weekends while I worked on this thesis—even though she may never know why! Finally, I would also like to thank all who have taught me at James Madison University. I believe that the education I have received will serve me well for many years to come. iii Contents Chapter 1 Introduction .......................................................................................................................................... 1 1.1 Foreword ......................................................................................................................................................... 1 1.2 Definitions of Terms ..................................................................................................................................... 2 1.2.1 Voting: Roles and Objects .................................................................................................................. 2 1.2.2 The Phases of Voting .......................................................................................................................... 2 1.2.3 Electronic Voting ................................................................................................................................. 3 1.3 Electronic Vote Tallying – Past and Present ............................................................................................. 8 1.3.1 Document Ballot Voting System ...................................................................................................... 9 1.3.2 Direct Recording Electronic Voting Systems ............................................................................... 10 1.4 Literature Review ......................................................................................................................................... 12 Chapter 2 Functional & Security Requirements .............................................................................................. 16 2.1 Functional Requirements ............................................................................................................................ 16 2.2 Security Requirements ................................................................................................................................. 18 Chapter 3 Modern Implementations ................................................................................................................. 21 3.1 Election Systems & Software: iVotronic® .............................................................................................. 21 3.2 Hart eSlate ..................................................................................................................................................... 22 3.3 Vote Box ........................................................................................................................................................ 23 3.4 Prêt à Voter ................................................................................................................................................... 24 3.5 Conclusions ................................................................................................................................................... 26 Chapter 4 Prototype Electronic Voting Implementation .............................................................................. 27 4.1 Building Blocks of Secure E-Voting ......................................................................................................... 27 4.1.1 Encryption Requirements ................................................................................................................. 27 4.1.2 Encryption Values and Calculations ............................................................................................... 29 4.1.3 Threshold Decryption ....................................................................................................................... 31 4.1.4 Re-Encryption Mix Network ........................................................................................................... 32 4.2 Modifications and Improvements ............................................................................................................. 33 4.2.1 Candidate Message ID’s.................................................................................................................... 33 4.2.2 Shuffling Operations of the Mixes.................................................................................................. 34 4.2.3 Vote Injection Detection in the Mix Network ............................................................................. 35 4.2.4 Message Authentication Hash Over (c1;c2) Pair ........................................................................... 37 4.3 Non-Technical Workflow ........................................................................................................................... 38 4.3.1 Terminals ............................................................................................................................................. 38 4.4 Technical Details: Prototype Implementation ........................................................................................ 40 4.4.1 Prevote ................................................................................................................................................. 43 4.4.2 Keysplitter ........................................................................................................................................... 44 4.4.3 ShuffleCands ....................................................................................................................................... 44 iv 4.4.4 Votecast ............................................................................................................................................... 44 4.4.5 Mix[x] ................................................................................................................................................... 45 4.4.6 Receiver ............................................................................................................................................... 48 4.4.7 Threshold_Dec & Decrypter ........................................................................................................... 49 4.4.8 Voting Interface ................................................................................................................................. 49 4.4.9 Tallying Votes ..................................................................................................................................... 50 Chapter 5 Security of the Prototype .................................................................................................................. 52 5.1.1 Network Traffic Analysis ................................................................................................................. 52 5.1.2 Replay/Injection Attacks .................................................................................................................. 52 5.1.3 Man-in-the-Middle Attacks .............................................................................................................. 54 5.1.4 Timing Attacks ................................................................................................................................... 55 5.1.5 Internet History Attack ..................................................................................................................... 56 5.1.6 Binary Strings Analysis ...................................................................................................................... 57 Chapter 6 Summary & Direction for Future Study ........................................................................................ 59 6.1 Areas of Improvement ................................................................................................................................ 59 6.2 Summary ........................................................................................................................................................ 62 v List of Tables. Table 1: Analysis of Several Popular