Abstract
In this paper we analyze the security of the online Danish party endorsement system (DVE) and present two attacks: one technical, which we discovered during our study of the system in 2016 and which compromises the integrity of the endorsements stored in the DVE-database and another socio-technical, which allows parties to circumvent mechanisms to protect voters against abuse. To understand these attacks, we introduce the legal and technical frameworks of the DVE-system, analyze its problems, and describe a sequence of events that has led to endorsing three new parties that stood in the 2019 Danish Parliament election.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
Notes
- 1.
See European Parliament election law §11, Sect. 1.
- 2.
Neither the authors nor their affiliations were involved in this project, neither during procurement, nor development, nor quality assurance.
- 3.
See https://www.nemid.nu.
- 4.
See https://cpr.dk/.
- 5.
- 6.
- 7.
See Vælgererklæringsbekendtgørelsen, https://www.retsinformation.dk/Forms/R07-10.aspx?id=176933.
- 8.
See Recommendation CM/Rec(2017)5[1] of the Committee of Ministers to member States on standards for e-voting (Adopted by the Committee of Ministers on 14 June 2017 at the 1289th meeting of the Ministers’ Deputies).
- 9.
- 10.
- 11.
- 12.
- 13.
- 14.
- 15.
References
Benaloh, J., Rivest, R.L., Ryan, P.Y.A., Stark, P.B., Teague, V., Vora, P.L.: End-to-end verifiability. CoRR, abs/1504.03778 (2015)
Clouser, M., Krimmer, R., Nore, H., Schürmann, C., Wolf, P.: The use of open source technology in elections. Resources on electoral processes. International IDEA, Stockholm (2014). ISBN 978-91-87729-68-3
Esteve, J.B., et al.: Certification of ICTs in Elections. International Institute for Democracy and Electoral Assistance (IDEA), Stockholm (2015)
Rivest, R.L., Wack, J.P.: On the notion of ‘software independence’ in voting systems, July 2006. http://vote.nist.gov/SI-in-voting.pdf
Acknowledgements
We would like to thank Christine Boeskov and Søren Stauning from ØIM for their comments on earlier versions of this paper.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2019 Springer Nature Switzerland AG
About this paper
Cite this paper
Schürmann, C., Bruni, A. (2019). Technical and Socio-Technical Attacks on the Danish Party Endorsement System. In: Krimmer, R., et al. Electronic Voting. E-Vote-ID 2019. Lecture Notes in Computer Science(), vol 11759. Springer, Cham. https://doi.org/10.1007/978-3-030-30625-0_13
Download citation
DOI: https://doi.org/10.1007/978-3-030-30625-0_13
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-030-30624-3
Online ISBN: 978-3-030-30625-0
eBook Packages: Computer ScienceComputer Science (R0)