Reversing, Breaking, and Fixing the French Legislative Election E-Voting Protocol
Alexandre Debant, Lucca Hirschi
摘要
We conduct a security analysis of the e-voting protocol used for the largest political election using e-voting in the world, the 2022 French legislative election for the citizens overseas. Due to a lack of system and threat model specifications, we built and contributed such specifications by studying the French legal framework and by reverse-engineering the code base accessible to the voters. Our analysis reveals that this protocol is affected by two design-level and implementation-level vulnerabilities. We show how those allow a standard voting server attacker and even more so a channel attacker to defeat the election integrity and ballot privacy due to 5 attack variants. We propose and discuss 5 fixes to prevent those attacks. Our specifications, the attacks, and the fixes were acknowledged by the relevant stakeholders during our responsible disclosure. They implemented our fixes to prevent our attacks for future elections. Beyond this protocol, we draw general lessons, recommendations, and open questions from this instructive experience where an e-voting protocol meets the real-world constraints of a large-scale, political election.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Can we cast a ballot as intended and be receipt free?Henri Devillez, Olivier Pereira, Thomas Peters, Quentin YangS&P 2024 · 被引用 4 次
- Election Eligibility with OpenID: Turning Authentication into Transferable Proof of EligibilityVéronique Cortier, Alexandre Debant, Anselme Goetschmann, Lucca HirschiUSENIX Security 2024 · 被引用 2 次
它引用的顶会 Paper3
- How not to prove your election outcomeThomas Haines, Sarah Jamie Lewis, Olivier Pereira, Vanessa TeagueS&P 2020 · 被引用 57 次
- Voting: You Can't Have Privacy without Individual VerifiabilityVéronique Cortier, Joseph LallemandCCS 2018 · 被引用 36 次
- Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent 等EUROCRYPT 2021 · 被引用 22 次
相关 Paper
- Kryvos: Publicly Tally-Hiding Verifiable E-VotingNicolas Huber, Ralf Küsters, Toomas Krips, Julian Liedtke 等CCS 2022 · 被引用 23 次
- Machine-Checked Proofs of Privacy for Electronic Voting ProtocolsVéronique Cortier, Constantin Catalin Dragan, François Dupressoir, Benedikt Schmidt 等S&P 2017 · 被引用 50 次
- The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal ElectionsMichael A. Specter, James Koppel, Daniel J. WeitznerUSENIX Security 2020
- VoteAgain: A scalable coercion-resistant voting systemWouter Lueks, Iñigo Querejeta-Azurmendi, Carmela TroncosoUSENIX Security 2020
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 被引用 24 次
