You Go to Elections with the Voting System You Have: Stop-Gap Mitigations for Deployed Voting Systems

You Go to Elections with the Voting System You Have: Stop-Gap Mitigations for Deployed Voting Systems
复制标题

您使用现有的投票系统参加选举:已部署投票系统的权宜之计

DOI:
--
复制
发表时间:
2008
期刊:
USENIX Workshop on Accurate Electronic Voting Technology
影响因子:
--
通讯作者:
D. Wagner
D. Wagner
中科院分区:
--
文献类型:
--
作者:
J. A. Halderman;E. Rescorla;H. Shacham;D. Wagner

文献摘要

被引文献

相似文献

鉴于最近对已部署的电子投票系统进行的审查发现的系统性漏洞,确保投票进程安全的最可靠办法是废弃现有系统并设计新的系统。不幸的是,设计新系统将需要数年时间,而且许多司法管辖区在不久的将来不太可能负担得起新设备。在这篇文章中,我们询问司法管辖区如何最大限度地利用他们已经拥有的设备,直到他们能够更换它。从目前的实践出发,我们提出了涉及新的但现实的程序、对现有软件进行适度更改、不更改现有硬件的防御措施。我们的技术极大地改进了对外部攻击的保护:它们提供了对病毒传播的遏制,提高了投票列表的完整性,并提供了对个别受攻击设备的一些检测。它们不能防止内部人员进入选举管理系统,这似乎需要对现有系统进行更大的改革。
In light of the systemic vulnerabilities uncovered by recent reviews of deployed e-voting systems, the surest way to secure the voting process would be to scrap the existing systems and design new ones. Unfortunately, engineering new systems will take years, and many jurisdictions are unlikely to be able to afford new equipment in the near future. In this paper we ask how jurisdictions can make the best use of the equipment they already own until they can replace it. Starting from current practice, we propose defenses that involve new but realistic procedures, modest changes to existing software, and no changes to existing hardware. Our techniques achieve greatly improved protection against outsider attacks: they provide containment of viral spread, improve the integrity of vote tabulation, and offer some detection of individual compromised devices. They do not provide security against insiders with access to election management systems, which appears to require significantly greater changes to the existing systems.