Electronic Filing Systems for Campaign and Finance Reports Subcommittee Report on Security and Authentication in Filing Systems Information Network of Arkansas Bob Sanders, General Manager Karl Hills, Director of Technology Blain Purtle, Security Analyst
Topics How user authentication works Risks and mitigation strategies Approaches in other states
The Filing Process: Paper
Notaries provide user validation in paper filing
The Filing Process: Electronic
Types of keys: Login & password Two-factor authentication PIN code Digital certificate / PKI
The Filing Process: Electronic The Key: Grants access Uniquely tied to the filer Logs access and actions taken
The Filing Process: Electronic User Validation is critical: Notary or in-person issuance Mailed form Wet signature
The Filing Process: Electronic
IP Address: Browser signature:
The Filing Process: Electronic notice / receipt
The Arkansas Electronic Records and Signatures Act “Electronic signature” means an electronic or digital method executed or adopted by a party with the intent to be bound by or to authenticate a record, which is unique to the person using it, is capable of verification, is under the sole control of the person using it, and is linked to data in such a manner that if the data are changed the electronic signature is invalidated. Act 718 of 1999
Risks & Strategies RiskMitigation Strategy Bad actor impersonates a filer at issuance State is the gate keeper Notary or in-person issuance Key is lost/stolen/compromised End-to-end encryption Password complexity Rotation schedule Two-factor (SMS, other) System is compromised; polluted with fraudulent data Already a risk with paper systems Notification to filer for any change Electronic forensics to aid investigation Immutable logs Notification settings are changed or disabled. State is the gate keeper Re-validate when changing notification or address settings.
Approaches in Other States Michigan: Signature form. Follows Federal rules. Tennessee: Signature form. Rhode Island: System generates paper filing which is then submitted with electronic filing. Indiana: Signature form. South Carolina: Signature and SSN required 98,000 filings over 9 years. No reports of fraud.
Questions