260 likes | 464 Views
Yossi Oren and Avishai Wool, . Attacks on RFID-Based Electronic Voting Systems. IEEE RFID’2010, Orlando FL. snipurl.com/e-voting. http://eprint.iacr.org/2009/422. Agenda. What’s the Israeli e-Voting Scheme? How can we break it cheaply and completely?. Not on the Agenda.
E N D
Yossi Oren and Avishai Wool, Attacks on RFID-Based Electronic Voting Systems IEEE RFID’2010, Orlando FL snipurl.com/e-voting http://eprint.iacr.org/2009/422
Agenda • What’s the Israeli e-Voting Scheme? • How can we break it cheaply and completely?
Not on the Agenda • Why the new scheme is legally unsound • Why our (ex-)ministers are all corrupt • The biometric database
Elections • What’s a good election scheme? • General • Free • Equal • Fair
Preliminaries • Definition: An electionE is an NPelection, if… N P • Conjecture: An election is only secure if it is NP-secure • Claim: The Israeli Scheme is NP-insecure
How Do We Vote Today? • Israel votes by national list proportional representation
How Do We Vote Today? N N P
How Do We Vote Today? • 72.1% participation rate • Less than 1.3% disqualified votes • (including protest “blank ballot” votes) • 99% final results 6 hours after poll closes • Public Trust N P
Attacks on the Voting System • Relay Attacks • Ballot Sniffing • Single Dissident • Ballot Stuffing • Non-Relay Attacks • Zapper • Remote Jamming • Implementation Attacks • Relay Attacks • Ballot Sniffing • Single Dissident • Ballot Stuffing • Non-Relay Attacks • Zapper • Remote Jamming • Implementation Attacks
The Ballot Sniffing Attack N P N N N P P N N P P P P N N N N N N
The Ballot Stuffing Attack P P N N P P P N P P P N N N P N P
The Zapper Attack P P P P P P P P
Implementation Attacks • Session Hijacking • Replay Attacks • Semantic Insecurity • …
Conclusion • Is the new e-voting scheme a good scheme? • General • Free • Equal • Fair • Is the new e-voting scheme a good scheme? • General • Free • Equal • Fair
Thank You! snipurl.com/e-voting http://eprint.iacr.org/2009/422