Assessing procedural risks and threats in e-voting: challenges and an approach

  • Authors:
  • Komminist Weldemariam;Adolfo Villafiorita;Andrea Mattioli

  • Affiliations:
  • Fondazione Bruno Kessler, IRST and ICT International Doctorate School, University of Trento;Fondazione Bruno Kessler, IRST;Fondazione Bruno Kessler, IRST

  • Venue:
  • VOTE-ID'07 Proceedings of the 1st international conference on E-voting and identity
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Performing a good security analysis on the design of a system is an essential step in order to guarantee a reasonable level of protection. However, different attacks and threats may be carried out depending on the operational environment in which the system is used, i.e. the procedures that define how to operate the systems. We are interested in reasoning about the security of e-Voting procedures, namely on the risks and attacks that can be carried out during an election. Our focus is more on people and organizations than on systems and technologies. In this paper we describe some ongoing work that we are carrying out within the ProVotE project (a project sponsored by the Autonomous Province of Trento to switch to e-Voting for local elections) to analyze and (possibly) improve procedural security of electronic elections. To do so, we are providing models of the Italian electoral laws using the UML and we are developing a custom methodology for analyzing threats from the models. Our reasoning approach is based on asset mobility, asset values and existence of multiple instances.