Integrity of electronic voting systems: fallacious use of cryptography

Integrity of electronic voting systems: fallacious use of cryptography
复制标题

电子投票系统的完整性:密码学的错误使用

DOI:
10.1145/2245276.2232013
复制
发表时间:
2012
期刊:
Proceedings of the Sixth International Workshop on Security and Privacy Analytics
影响因子:
--
通讯作者:
Alexander A. Shvartsman
Alexander A. Shvartsman
中科院分区:
--
文献类型:
--
作者:
S. Davtyan;A. Kiayias;L. Michel;A. Russell;Alexander A. Shvartsman

文献摘要

被引文献

相似文献

近年来,美国所有的选举都采用了电子投票系统。尽管在大多数这样的系统中使用了加密完整性检查,但有几份报告记录了电子投票终端的严重安全漏洞。我们概述了在大多数(如果不是全部的话)电子选举系统中发现的典型安全和选举漏洞,并提供了一个案例研究来说明这些漏洞。我们对美国350多个司法管辖区的1200多万选民使用的AccuVote TSx投票终端进行了实际安全分析,发现系统中存在某些新的完整性漏洞。我们基于这些漏洞提出了两种攻击:一种攻击交换了两名候选人的选票,另一种攻击从名单上删除了一名候选人的名字。这些攻击不需要修改投票终端的操作系统(就像之前的许多攻击一样),并且能够绕过终端中实现的加密完整性检查。攻击可以在几分钟内发起,并且只需要一台能够挂载PCMCIA卡文件系统的计算机(大多数当前操作系统的默认功能)。本文介绍的攻击是通过对投票终端的直接实验发现的,并且没有访问任何内部文档或制造商的源代码。
In recent years, electronic voting systems have been deployed in all U.S. elections. Despite the fact that cryptographic integrity checks are used in most such systems, several reports have documented serious security vulnerabilities of electronic voting terminals. We present an overview of the typical security and election vulnerabilities found in most, if not all, electronic election systems, and present a case study that illustrates such vulnerabilities. Our hands-on security analysis of the AccuVote TSx voting terminal --- used by more than 12 million voters in over 350 jurisdictions in the U.S. --- demonstrates certain new integrity vulnerabilities that are present in the system. We present two attacks based on these vulnerabilities: one attack swaps the votes of two candidates and another erases the name of one candidate from the slate. These attacks do not require modification of the operating system of the voting terminal (as was the case in a number of previous attacks) and are able to circumvent the cryptographic integrity checks implemented in the terminal. The attacks can be launched in a matter of minutes and require only a computer with the capability to mount a PCMCIA card file system (a default capability in most current operating systems). The attacks presented here were discovered through direct experimentation with the voting terminal and without access to any internal documentation or the source code from the manufacturer.