论文标题

安全调查和逐牌系统的分析

Security Survey and Analysis of Vote-by-Mail Systems

论文作者

Blessing, Jenny, Gomez, Julian, Patiño, McCoy, Nguyen, Tran

论文摘要

在美国,通过邮件进行投票已经吸引了数十年,并且已成为COVID-19大流行期间的首选投票方法。在本文中,我们研究了邮件投票过程中使用的电子系统的安全性,包括在线选民注册和在线投票跟踪系统。这些制度的目标是促进选民注册并增加公众对选举的信心,这是值得称赞的。它们无疑提供了关键的公共利益。出于这些原因,了解邮寄投票过程的安全性和隐私姿势至关重要。我们发现,某些州的在线选民注册系统具有使对手更改或有效防止选民注册的漏洞。我们还发现,投票跟踪系统提出了严重的隐私问题,围绕着访问选民数据的访问。尽管这里讨论的脆弱性不太可能使对手改变投票,但一些可能会剥夺选民的权利,并降低选民对美国选举基础设施的信心,从而破坏这些系统的目的。

Voting by mail has been gaining traction for decades in the United States and has emerged as the preferred voting method during the COVID-19 pandemic. In this paper, we examine the security of electronic systems used in the process of voting by mail, including online voter registration and online ballot tracking systems. The goals of these systems, to facilitate voter registration and increase public confidence in elections, are laudable. They indisputably provide a critical public good. It is for these reasons that understanding the security and privacy posture of the mail-in voting process is paramount. We find that online voter registration systems in some states have vulnerabilities that allow adversaries to alter or effectively prevent a voter's registration. We additionally find that ballot tracking systems raise serious privacy questions surrounding ease of access to voter data. While the vulnerabilities discussed here are unlikely to enable an adversary to modify votes, several could have the effect of disenfranchising voters and reducing voter confidence in U.S. elections infrastructure, thereby undermining the very purpose of these systems.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源