26
Internet Voting in Estonia Tarmo Milva Deputy project manager Estonian National Electoral Commitee

Internet Voting in Estonia

Embed Size (px)

DESCRIPTION

Internet Voting in Estonia. Tarmo Milva Deputy project manager Estonian National Electoral Commitee. E-stonia ?. Population: 1.35M Everyday Internet usage: 54% Internet banking: 86% Mobile penetration: 95% 1000+ Free Internet Access points PKI penetration: >65% - PowerPoint PPT Presentation

Citation preview

Page 1: Internet Voting in Estonia

Internet Votingin Estonia

Tarmo Milva

Deputy project manager

Estonian National Electoral Commitee

Page 2: Internet Voting in Estonia

E-stonia ?

Population: 1.35M Everyday Internet usage: 54% Internet banking: 86% Mobile penetration: 95% 1000+ Free Internet Access points

PKI penetration: >65% Biggest national eID card roll-out in the

Europe !

Page 3: Internet Voting in Estonia

Internet Voting?

In October 2005 Estonia had first-ever pan-national Internet Voting with binding results

~80% of voters had a chance to vote via Internet due to the ID-card

~2% of participated voters used that possibility

Page 4: Internet Voting in Estonia

ID-card Project

Started in 1997 Law on personal identification documents:

Feb, 1999 Digital Signature Act: March, 2000 Government accepted plan for

launching ID-card: May, 2000 First card issued: Jan 28, 2002 Apr 2006: 910 000+ cards have been issued

Page 5: Internet Voting in Estonia

The Card

“Compulsory” for all residents

Contains: Personal data file Certificate for authentication

(along with e-mail address [email protected])

Certificate for digital signature

Page 6: Internet Voting in Estonia

Usage of the ID-card

Major ID-document Replacement of

(transportation) tickets library cards healt insurance card driver documents etc...

Authentication token for all major e-services Digital signature tool

Page 7: Internet Voting in Estonia

Internet Voting ?

Not a nuclear physics Just another application for ID-card

...with some special requirements & measures...

Page 8: Internet Voting in Estonia

What it takes ?

Procedures

Technology Voters

Politicians & Laws

Token fori-voters

Trust

Page 9: Internet Voting in Estonia

Legal foundation 2002

1) voter can use internet for voting

2) voter is authenticated using ID-card

3) voter confirms his selection with digital signature

4) e-voting takes place during absentee voting i.e. days 6.-4. before the Election Day

Page 10: Internet Voting in Estonia

Big Fight in 2005

Amendments to the electoral law to reflect the reality

Long discussions in the Parliament The President rejected the amended law

twice National Court decided that the amendments

are correspondant to the Constitutional Law Issue: With Internet voting you can vote repeaditly

Page 11: Internet Voting in Estonia

I-voting Main Principles

All major principles of paper-voting are followed I-voting is allowed during period before Voting Day The user uses ID-card

System authenticates the user Voter confirms his choice with digital signature

Repeated e-voting is allowed Only last e-ballot is counted

Manual re-voting is allowed If vote is casted in paper during the Election Day, e-vote(s)

will be revoked

Page 12: Internet Voting in Estonia

Voter registration

Missing

All citizen (residents) should register their place of living in central population register

Only voters with registered addresses are eligible

Population register is used

Page 13: Internet Voting in Estonia

To vote via Internet voter needs:

An Estonian ID card with valid certificates and PIN-codes

Computer used for voting must have:

A smart card reader A driver for ID card (free to download from page www.id.ee/installer)

A Windows,Linux or MacOSX operating system

Page 14: Internet Voting in Estonia

I Website for voting

www.valimised.ee

www.valimised.ee

Page 15: Internet Voting in Estonia

II Authentication

Put your card into card reader

Insert PIN 1 for authentication

****

Page 16: Internet Voting in Estonia

III Ballot completion

Choose a candidate

Page 17: Internet Voting in Estonia

IV Authentication Confirm your choice

Insert PIN 2

*****

Page 18: Internet Voting in Estonia

V Confirmation

Page 19: Internet Voting in Estonia

Encryptedvote

Digital signature

E-voters

E-votes Results

Private keyPublic key

Envelope scheme

Page 20: Internet Voting in Estonia

AuditKey Management

List ofCandidates

List ofVoters

VoteForwarding

ServerVote

StoringServer

VoteCounting

Application

Voterapplication

Auditapplication

log

loglog

Central System

Architecture

Page 21: Internet Voting in Estonia

Principles for selecting technology for I-voting

Involve all major influencers and “specialists” Keep it as simple as possible Build it on secure&stable platforms (Debian) No:

Databases (engines) 9GL envirmonments – use C & Python 3rd party libraries too much

Page 22: Internet Voting in Estonia

Managing Procedures

All fully documented Crash course for

observers-politicians & auditors All security-critical procedures:

Logged Audited & observed Videotaped

All major IS-specialists involved for network-monitoring 24/7 for dDOS or trojans

Page 23: Internet Voting in Estonia

Physical Security

Governmental security hosting Two independant departement guarding the

server room Strict requirements for entering the server

premises Auditor(s), cam-man, operator, police officer

Sealing of hardware

Page 24: Internet Voting in Estonia

E-voting frequency by hours

7219 9 5 5 4 19

60

320

932

780

641

554

635

521 540 530 532

707

1083

530 546

416

221

0

200

400

600

800

1000

1200

0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23

Some statistics

Page 25: Internet Voting in Estonia

Lessons learned

I-voting is not a killer-application. It is just another way for people to vote

People’s attitude and behavior change in decades and generations, not in seconds

I-voting will be as natural as Internet-banking but even more secure

Internet voting is there to stay