12/9-10/2009 TGDC Meeting Alternatives to Software Independence Nelson Hastings National Institute of Standards and Technology
12/9-10/2009 TGDC Meeting Motivation Page 2 Alternatives to Software Independence to retain the VVSG’s focus on security, verifiability, and auditability Issues: Impacts on innovation and usability
12/9-10/2009 TGDC Meeting Page 3 Strategy Make auditability, not SI, an overarching requirement Moves focus to the trustworthiness of audit records Allows some reliance on software based on trust in audit records How is auditability achieved? Software independent approaches: IVVR requirements End-to-End protocols (E2E) Independent Verification (IV) Secure Audit Port
12/9-10/2009 TGDC Meeting Page 4 Strategy SI - Auditability Innovation Class IVVR Auditability SI IVVR Independent Verification (IV) Secure Audit Port End-to-End (E2E) Innovation Class Current draft next VVSG: With inclusion of alternatives:
12/9-10/2009 TGDC Meeting Possible Ramifications SI requirement on VVSG could be replaced with requirements for auditability Unclear what the auditability requirements should be for the VVSG Unclear what the impact will be on the cost of developing and testing of the systems Impact other areas of the VVSG that need further study, e.g., usability, accessibility For all alternatives, more research is needed Page 5
12/9-10/2009 TGDC Meeting End-to-End Workshop Two day workshop in October 2009 Brought the security, usability, accessibility, and election communities together Purpose to define what is an end-to-end voting systems Identified desired security properties Discussed usability and accessibility issues Outcome: More research needs to be done Page 6