Security Assessment of the Diebold Optical Scan Voting Terminal

نویسندگان

  • A. Kiayias
  • L. Michel A. Russell
  • A. A. Shvartsman
چکیده

We present an independent security evaluation of the AccuVote Optical Scan voting terminal (AV-OS). We identify a number of new vulnerabilities of this system which, if exploited maliciously, can invalidate the results of an election process utilizing the terminal. Furthermore, based on our findings an AV-OS can be compromised with off-the-shelf equipment in a matter of minutes even if the machine has its removable memory card sealed in place. The basic attack can be applied to effect a variety of results, including entirely neutralizing one candidate so that their votes are not counted, swapping the votes of two candidates, or biasing the results by shifting some votes from one candidate to another. Such vote tabulation corruptions can lay dormant until the election day, thus avoiding detection through pre-election tests. Based on these findings, we describe new safe-use recommendations for the AV-OS terminal. Specifically, we recommend installation of tamper-resistant seals for (i) removable memory cards, (ii) serial port, (iii) telephone jacks, as well as (iv) screws that allow access into the terminal’s interior; failure to seal any single one of these components renders the terminal susceptible to the attack outlined above. An alternative is to seal the entire Optical Scan system (sans ballot box) into a tamper-resistant container at all times other than preparation for election and deployment in an election. An unbroken chain of custody must be enforced at all times. Post-election audits are also strongly advised. The Diebold AccuVote Optical Scan voting terminals described in this report are going to be used in November 2006 election in several precincts in the State of Connecticut. The terminals are provided by the LHS Associates of Massachusetts. VoTeR Center personnel assisted the Office of the Connecticut Secretary of the State in developing safe use procedures for the Optical Scan terminals for this election. The procedures in place for the election includes strict physical custody policy, tamper-resistant protection of the equipment, and random post-election audits.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Principal Investigator ’ s Statement on Protection of Security - Sensitive Information

We present an independent security evaluation of the AccuVote Optical Scan voting terminal (AV-OS).We identify a number of new vulnerabilities of this system which, if exploited maliciously, can invalidatethe results of an election process utilizing the terminal. Furthermore, based on our findings an AV-OScan be compromised with off-the-shelf equipment in a matter of minutes even if...

متن کامل

An Authentication and Ballot Layout Attack Against an Optical Scan Voting Terminal

Recently, two e-voting technologies have been introduced and used extensively in election procedures: direct recording electronic (DRE) systems and optical scanners. The latter are typically deemed safer as many recent security reports have discovered substantial vulnerabilities in a variety of DRE systems. In this paper we present an attack against the Diebold Accuvote optical scan voting term...

متن کامل

Integrity Vulnerabilities in the Diebold TSX Voting Terminal

This report presents certain integrity vulnerabilities in the Diebold AV-TSx Voting Terminal1. We present two attacks based on these vulnerabilities: one attack swaps the votes of two candidates and another erases the name of one candidate from the slate. These attacks do not require the modification of the operating system of the voting terminal (as it was the case in a number of previous atta...

متن کامل

Diebold TSx Evaluation SECURITY ALERT : May 11 , 2006 Critical Security Issues with Diebold TSx

Executive Summary Due to the nature of this report it is distributed in two different versions. Details of the attack are only in the restricted distribution version considered to be confidential. This document describes several security issues with the Diebold electronic voting terminals TSx and TS6. These touch-pad terminals are widely used in US and Canadian elections and are among the most ...

متن کامل

Attacking the Diebold Signature Variant – RSA Signatures with Unverified High-order Padding

We examine a natural but improper implementation of RSA signature verification deployed on the widely used Diebold Touch Screen and Optical Scan voting machines. In the implemented scheme, the verifier fails to examine a large number of the high-order bits of signature padding and the public exponent is three. We present an very mathematically simple attack that enables an adversary to forge si...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006