Melanie Volkamer (Research Manager) University of Passau, Innstraße 43, 94032 Passau, Germany, Tel: +49 851/509-3021 Webpage:

Slides:



Advertisements
Similar presentations
The Public Finance and Empoyment Database of the OECD Dirk Kraan National Accounts Working Party Paris 1 December 2010.
Advertisements

Programme: 145 sessions & social events
United Kingdom New Zealand United Kingdom New Zealand Iceland.
“…by 2014, about 34% of all new business software purchases will be consumed via SaaS…” - IDC, June 2010* Used by Over 50% of the Fortune % CIOs.
© The Treasury Setting the Scene: A fiscal and public sector management perspective on the justice sector in New Zealand.
Reversing Offshore Economics and Improving Financial Regulation: Curtailing Illicit Financial Flows Petr Janský Economist and Consultant Charles University.
Common Criteria Richard Newman. What is the Common Criteria Cooperative effort among Canada, France, Germany, the Netherlands, UK, USA (NSA, NIST) Defines.
German Research Center for Artificial Intelligence Protection Profile for Central Requirements for Online Voting German Research Center for Artificial.
Chapter 1 The Pay Model.
What is the degree of your global awareness?
by the way we 1.Introduction: Cultural Norms and Values - Stereotyping American culture Chinese culture.
Welcome to CERN Research Technology Training Collaborating.
Hello to UMD from Cirrus. Brief History of Cirrus Cirrus founded in 1984 Began development of the VK-30 in 1988 Began development of ST50 in
© Lloyd’s Regional Watch Content Guide CLICK ANY BOX AMERICAS IMEA EUROPE ASIA PACIFIC.
Page 1 Recording of this session via any media type is strictly prohibited. ACA Impact on Workers’ Compensation.
COST 356 EST - Towards the definition of a measurable environmentally sustainable transport CONTACTS Dr Robert Joumard, chairman, INRETS, tel
1 Anthony Apted/ James Arnold 26 September 2007 Has the Common Criteria Delivered?
Solution Cloud services and Windows 7 * Pricing may vary by region.
A Global Approach for Ex-Products – IECEx UNECE WP.6 Geneva June 2006 Proposal for a new activity: “International legal requirements for explosion.
The Human Factors Components of a Safety Management System: The US Perspective Dr. William B. Johnson Chief Scientific & Technical Advisor for Human Factors.
OECD Review of Russian Statistics Peer Review Mission to Russia April 2012 Tim Davis Head, Global Relations, Statistics Directorate.
GLP & Quality Assurance
Hello UMD from Cirrus Aircraft
Environmental issues and local development Partnerships and the Green Economy Styria, 11 th October 2010 Gabriela Miranda
Conformity Assessment and Accreditation Mike Peet Chief Executive Officer South African National Accreditation System.
DEVELOPING CREDIT INSURANCE IN AFRICA AND THE MEDITERRANEAN Tunis, October 2000.
Marine & Energy Practice Risk and Insurance Seminar Houston 20 September 2004 John Lapsley Chairman Marine & Energy.
Common Criteria Recognition Arrangement 8 th ICCC Rome, 25 th September 2007 Report by the MC Chairman Gen. Luigi Palagiano.
Grants LXIV International Council Meeting 19th – 26th October, Bodrum Turkey.
WELCOME TO THE MAP LIBRARY.  The map library provides you with a range of ready-to-use maps that can be used in your PowerPoint presentations.  The.
You say to-mah-to, I say to-mae-to: why isn’t there a single solution to Information Security Assurance? Apostol Vassilev atsec information security &
Perfection in Automation
Match the countries and their capitals: Italy France Germany Spain The Netherlands The Czech Republic India Belgium Norway Bern Amsterdam Rome Prague.
Chapter 15 Development of the profession of O&M around the world.
TM8104 IT Security EvaluationAutumn CC – Common Criteria (for IT Security Evaluation) The CC permits comparability between the results of independent.
International Comparison of Health Care Gene Chang.
Chapter 27 Chapter 27 Geographic Variability in Hip and Vertebral Fractures Copyright © 2013 Elsevier Inc. All rights reserved.
< Return to Largest Religious CommunitiesLargest Religious Communities The Largest Atheist / Agnostic Populations Top 50 Countries With Highest Proportion.
Impact of the Crisis on Children in Europe Yekaterina Chzhen ChildONEurope Seminar Paris - November 26, 2015.
The (IMG) Systems for Comparative Analysis of Microbial Genomes & Metagenomes: N America: 1,180 Europe: 386 Asia: 235 Africa: 6 Oceania: 81 S America:
Country EPS-12 Total (with ICPS) Hungary7979 Germany5559 Romania3841 Ukraine2527 United Kingdom1930 Finland1842 France1616 Italy1616 Poland1313 Switzerland1314.
Figure 1. PARTICIPATING STEM CELL DONOR REGISTRIES Number of registries Year ©BMDW.
Office 365 Education E5 Overview for Partners April 2016 Microsoft Confidential: Partner use only.
Bed Linen Markets in the World to 2017 Bharat Book Bureau.
Global Aluminium Foil Market to Market Size, Growth, and Forecasts in Nearly 60 Countries Published on : Jul 2014.
Global Aluminium Pipe and Tube Market to 2018 (Market Size, Growth, and Forecasts in Nearly 60 Countries) Published Date: Jul-2014 Reports and Intelligence.
IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components.
IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components.
IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components.
Another BRIC on the Web: The Brazilian Presence in International Agency Statistical Sites Harold Colson International Relations Librarian University of.
Immigration by Bill Bosshardt Election Economics.
IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components.
Presented By: Manish Gidwani 10 Kapil Israni 16
Global Golf Equipment Market to 2019 The report focuses on global major leading industry players with information such as company profiles, product picture.
Best Sustainable Development Practices for Food Security UV-B radiation: A Specific Regulator of Plant Growth and Food Quality in a Changing Climate The.
Tax Policy Challenges in a Changing World. Unintended Consequences of Tax Rob Marston, “Window Tax”, 1 September 2010 uploaded via Flickr, creative commons.
Global Vitamin and Provitamin Market Size, Share, Global Trends, Company Profiles, Demand, Insights, Analysis, Research, Report, Opportunities, 2018 Published.
Assessment Of The Global Construction Market And Growth Trends In Global Economy, 2021 Published: Apr 2017 Single User PDF: US$ 4950 Order this report.
NSO data collections of subjective well-being
Certification CS-100/ CSE-200 /CSC-1
Sustainable use of Natural Resources
Partnerships for VoIP Security VoIP Protection Profiles
Six Sigma Total Error Percent Process Sigma 1,000, ,000 10% 2.78
The 1680 Family’s Reach.
Electrification Products
Citi Virtual Card Accounts – Continued Global Expansion
A Global Approach for Ex-Products
COUNTRİES & NATİONALİTİES
ATLAS Resources Review Board CERN-RRB April 2019
Electrification business
Presentation transcript:

Melanie Volkamer (Research Manager) University of Passau, Innstraße 43, Passau, Germany, Tel: / Webpage: Common Criteria Protection Profile for a Basic Set of Security Requirements for Online Voting Products CoE Meeting 16th October 2008, Madrid

Project Formation DFKI project funded by the BSI Duration Starting in January 2006 Certification in April 2008 Advisory Board: Researchers: Koblenz, Gießen, Wien, … Users: GI, Ministry of workers & social affairs, … Companies: mainly Micromata and T-Systems Others: CoE, e-Voting.cc, PTB, ASIT, BSI, … Based on existing requirement documents: CoE, PTB and GI catalogue Oct16th 20082CoE Meeting Madrid

Motivation Oct16 th 20083CoE Meeting Madrid Council of Europe Recommendations Swiss, Austrian, German Election Regulations Austrian Election Regulations IEEE Voting Equipment Standards Voting System Standards Network Voting System Standards PTB requirement catalogue ….. Good starting point but only lists of requirements  Problems: - Trust model is not defined - Evaluation method and depth is not made explicit  No meaningful evaluation  No comparable evaluation results

Solution: Common Criteria International standard (ISO/IEC15408) for Information Technology Security Evaluation (CC) Australia, Canada, France, Germany, Japan, Republic of Korea, The Netherlands, New Zealand, Norway, Spain, United Kingdom, United States of America; Austria, Czech Republic, Denmark, Greece, Hungary, India, Israel, Italy, Republic of Singapore, Sweden, Turkey Protection Profile = An implementation-independent set of security requirements for a category of TOEs that meet specific consumer needs. [TOE = target of evaluation] CoE Recommendations made first steps Oct16th 20084CoE Meeting Madrid

Basis Protection Profile Not „one“ general Protection Profile for Online Voting Because of different trust models and evaluation depths Depending on the election in mind (societies vs. parliamentary) Serves as basis which can be extended Takes only the voting phase and the counting phase into account. Oct16th 20085CoE Meeting Madrid

Protection Profile – Content Oct16th 20086CoE Meeting Madrid Trust Model Evaluation Depth

Content - Threats T.UnauthorisedVoter T.Proof T.IntegrityMessage T.SecretMessage T.AuthenticityServer T.ArchivingIntegrity T.ArchivingSecrecyOfVoting Oct16th 20087CoE Meeting Madrid

Content - Assumptions A.ElectionPreparation A.Observation / A.AuthData/A.ElectionOfficers A.VoteCastingDevice /ElectionServer / ServerRoom A.Availability / DataStorage A.AuthenticityServer / ProtectedCommunication A.SystemTime / AuditTrailProtection A.ArchivingSecrecyOfVoting A.BufferBallot Oct16th 20088CoE Meeting Madrid

Content - OSPs P.Abort / OverhasteProtection / Correction / ACK P.EndingElection P.EndOfElection / StartTallying P.SecrecyOfVotingElectionOfficer / IntegrityE.O./ IntermediateResult / AuthE.O. P.OneVoterOneVote P.Tallying P.Failure P.Audit Oct16th 20089CoE Meeting Madrid

Protection Profile – Content Oct16th CoE Meeting Madrid Trust Model Evaluation Depth

Content – Evaluation Depth CC EAL scale from 1 to 7 Evaluation Assurance Level 2+ ALC_CMC.3 (substituting ALC_CMC.2) ALC_CMS.3 (substituting ALC_CMS.2) ALC_DVS.1 ALC_LCD.1  Assumed attacker potential: basic Oct16th CoE Meeting Madrid

Election Authorities Does the trust model fits to your environment? Does EAL 2+ provides enough trust in the evaluation If not the PP can be extended by Shifting assumptions to threats Arising the EAL number Demand the systems in use to be certified according to this Protection Profile or an extended version Oct16th CoE Meeting Madrid

Thank your for your attention ? Questions ? p0037b_engl.pdf