Publication | Closed Access
TPM Meets DRE: Reducing the Trust Base for Electronic Voting Using Trusted Platform Modules
29
Citations
15
References
2009
Year
EngineeringInformation SecurityTrust Management ArchitectureVerificationInformation ForensicsElection Data IntegrityFormal VerificationTpm Meets DreHardware SecurityTrusted Platform ModulesComputing BaseElectronic VotingTrusted Execution EnvironmentSecure ComputingSecure Multi-party ComputationComputer EngineeringData PrivacyTrustComputer ScienceData SecurityCryptographyTrustworthy ComputingTrusted SystemTrusted PlatformTrust Base
We reduce the required trusted computing base for direct recording electronic (DRE) voting machines with a design based on trusted platform modules (TPMs). Our approach ensures election data integrity by binding the voter's choices with the presented ballot using a platform vote ballot (PVB) signature key managed by the TPM. The TPM can use the PVB key only when static measurements of the software reflect an uncompromised state and when a precinct judge enters a special password revealed on election day. Using the PVB with the TPM can expose authorized software, ballot modifications, vote tampering, and creation of fake election records early in the election process. Our protocol places trust in tamper resistant hardware, not in mutable system software. Although we are not the first to suggest using TPMs in voting, we are the first to provide a detailed engineering protocol that binds the voter choices with the presented ballot and uses the TPM to enforce election policy. We present the protocol, architecture, assumptions, and security arguments in enough detail to support further analysis or implementation.
| Year | Citations | |
|---|---|---|
Page 1
Page 1