Paper 2024/1398

Coercion-resistant i-voting with short PIN and OAuth 2.0

Matteo Bitussi, Center for Cybersecurity, Fondazione Bruno Kessler, Trento, Italy
Riccardo Longo, Center for Cybersecurity, Fondazione Bruno Kessler, Trento, Italy
Francesco Antonio Marino, Italian Government Printing Office and Mint, IPZS, Rome, Italy
Umberto Morelli, Center for Cybersecurity, Fondazione Bruno Kessler, Trento, Italy
Amir Sharif, Center for Cybersecurity, Fondazione Bruno Kessler, Trento, Italy
Chiara Spadafora, Universit`a degli Studi di Trento, Trento, Italy
Alessandro Tomasi, Center for Cybersecurity, Fondazione Bruno Kessler, Trento, Italy
Abstract

This paper presents an architecture for an OAuth 2.0-based i-voting solution using a mobile native client in a variant of the Ara´ujo-Traor´e protocol. We follow a systematic approach by identifying relevant OAuth 2.0 specifications and best practices. Having defined our framework, we identify threats applicable to our proposed methodology and detail how our design mitigates them to provide a safer i-voting process.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. E-Vote-ID 2023
Keywords
i-votingCoercion ResistanceOAuth 2.0.
Contact author(s)
mbitussi @ fbk eu
rlongo @ fbk eu
fa marino @ ipzs it
umorelli @ fbk eu
asharif @ fbk eu
chiara spadafora @ unitn it
altomasi @ fbk eu
History
2024-09-11: approved
2024-09-06: received
See all versions
Short URL
https://ia.cr/2024/1398
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2024/1398,
      author = {Matteo Bitussi and Riccardo Longo and Francesco Antonio Marino and Umberto Morelli and Amir Sharif and Chiara Spadafora and Alessandro Tomasi},
      title = {Coercion-resistant i-voting with short {PIN} and {OAuth} 2.0},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1398},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1398}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.