NIST VOTING PROGRAM MARY BRADY, PROGRAM MANAGER. Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  Engage the.

Slides:



Advertisements
Similar presentations
TGDC Meeting, December 2011 Usability and Accessibility (U&A) Research Update Sharon J. Laskowski, Ph.D.
Advertisements

IEEE P1622 Meeting, Oct 2011 IEEE P1622 Meeting October 24-25, 2011 Overview of IEEE P1622 Draft Standard for Electronic Distribution of Blank Ballots.
Affidavit Ballot Procedures The Mississippi Secretary of State’s Office Elections Division 2012.
TGDC Meeting, July 2011 Review of VVSG 1.1 Nelson Hastings, Ph.D. Technical Project Leader for Voting Standards, ITL
© Copyright 2009 TEM Consulting, LP - All Rights Reserved Presentation To Travis County, TX - May 27, 2009Rev 1 – 05/22/09 - HSB US Voting System Conformity.
Heath Hillman Assistant Secretary of State Elections Division
Chapter 10 Section 1: p  Early America: most voters were white, adult males who owned property ◦ White adult males who could not afford property,
United States Election Assistance Commission Pilot Program Testing and Certification Manual & UOCAVA Pilot Program Testing and Certification Manual & UOCAVA.
Voting System Qualification How it happens and why.
United States 1 Election Assistance Commission 1 Inspiring Change & Modernization in Election Administration Seattle, WA June 10, 2015.
12/9-10/2009 TGDC Meeting TGDC Recommendations Research as requested by the EAC John P. Wack National Institute of Standards and Technology
TGDC Meeting, Jan 2011 UOCAVA Pilot Projects for the 2012 Federal Election Report from the UOCAVA Working Group Andrew Regenscheid National Institute of.
Improving U.S. Voting Systems The Voters’ Perspective: Next generation guidelines for usability and accessibility Sharon Laskowski NIST Whitney Quesenbery.
TGDC Meeting, July 2011 Overview of July TGDC Meeting Belinda L. Collins, Ph.D. Senior Advisor, Voting Standards, ITL
TGDC Meeting, July 2011 Update on the UOCAVA Working Group Andrew Regenscheid Mathematician, Computer Security Division, ITL
Testing Summit Sacramento, CA November 28, 2005 Barbara Guttman National Institute of Standards and Technology
United States Election Assistance Commission EAC UOCAVA Documents: Status &Update EAC Technical Guidelines Development Committee Meeting (TGDC)
TGDC Meeting, Jan 2011 VVSG 2.0 and Beyond: Usability and Accessibility Issues, Gaps, and Performance Tests Sharon Laskowski, PhD National Institute of.
TGDC Meeting, July 2011 UOCAVA Roadmap Update Nelson Hastings, Ph.D. Technical Project Leader for Voting Standards, ITL
TGDC Meeting, July 2011 IEEE P.1622 Update John P. Wack Computer Scientist, Software and Systems Division, ITL
NIST HAVA-Related Work: Status and Plans June 16, 2005 National Institute of Standards and Technology
Making every vote count. United States Election Assistance Commission HAVA 101 TGDC Meeting December 9-10, 2009.
12/9-10/2009 TGDC Meeting NIST Research on UOCAVA Voting Andrew Regenscheid National Institute of Standards and Technology
Election Accessibility 2004 Christina Galindo-Walsh National Association of Protection and Advocacy Systems (NAPAS)
IEEE P1622 Meeting, Feb 2011 Common Data Format (CDF) Update John P. Wack National Institute of Standards and Technology
Improving U.S. Voting Systems Interoperability in Election Data and Devices TGDC Meeting July 20 – 21, 2015 Improving U.S. Voting Systems 1 John P. Wack.
Usability and Accessibility Working Group Report Sharon Laskowski, PhD National Institute of Standards and Technology TGDC Meeting,
County Canvassing Board Training 2010 Sheryl Moss Certification and Training Manager Office of the Secretary of State (360)
Briefing for NIST Acting Director James Turner regarding visit from EAC Commissioners March 26, 2008 For internal use only 1.
NC STATE BOARD OF ELECTIONS PRECINCT UNIFORMITY PROJECT 2008.
NIST Voting Program Activities Update February 21, 2007 Mark Skall Chief, Software Diagnostics and Conformance Testing Division.
Objectives Analyze how the administration of elections in the United States helps make democracy work. Define the role of local precincts and polling places.
TGDC Meeting, Jan 2011 Accessibility and Usability Considerations for UOCAVA Remote Electronic Voting Systems Sharon Laskowski, PhD National Institute.
Making every vote count. United States Election Assistance Commission EAC Voting System Certification TGDC Meeting December 9-10, 2009.
Oct 15-17, : Integratability and Data Export Page 1Next VVSG Training Voting devices must speak (produce records) using a commonly understood language,
TGDC Meeting, July 2010 Report of the UOCAVA Working Group John Wack National Institute of Standards and Technology DRAFT.
1 The Evolution of Voting Systems Paul DeGregorio Vice Chairman Donetta Davidson Commissioner The U.S. Election Assistance Commission.
NIST Voting Program Page 1 NIST Voting Program Lynne Rosenthal National Institute of Standards and Technology
TGDC Meeting, December 2011 Overview of December TGDC Meeting Belinda L. Collins, Ph.D. Senior Advisor, Voting Standards
NIST Voting Program Barbara Guttman 12/6/07
TGDC Meeting, July 2011 Voluntary Voting System Guidelines Roadmap Nelson Hastings, Ph.D. Technical Project Leader for Voting Standards, ITL
ABSENTEE VOTING PROCEDURES FOR UNIFORMED AND OVERSEAS CITIZENS Election Commissioners’ Association of Mississippi Annual Meeting Presented by: Liz Bolin.
TGDC Meeting, Jan 2011 Help America Vote Act (HAVA) Roadmap Nelson Hastings National Institute of Standards and Technology
TGDC Meeting, July 2010 Report on Other Resolutions from Dec 2009 TGDC Meeting John Wack National Institute of Standards and Technology
TGDC Meeting, Jan 2011 Common Data Format (CDF) Update John P. Wack National Institute of Standards and Technology
TGDC Meeting, Jan 2011 Review of UOCAVA Roadmap Nelson Hastings National Institute of Standards and Technology
NIST Voting Program Activities Update January 4, 2007 Mark Skall Chief, Software Diagnostics and Conformance Testing Division.
Next VVSG Training Standards 101 October 15-17, 2007 Mark Skall National Institute of Standards and Technology
1 DECEMBER 9-10, 2009 Gaithersburg, Maryland TECHNICAL GUIDELINES DEVELOPMENT COMMITTEE Commissioner Donetta Davidson.
The Administration of Elections Extent of Federal control Elections need to be free, honest, and accurate Most election law in the U.S. is State Law.
NIST VOTING PROGRAM MARY BRADY, PROGRAM MANAGER TGDC MEETING: FEBRUARY 2016.
EAC-requested VVSG Research Overview and Status June 2008 Mark Skall Chief, Software Diagnostics and Conformance Testing Division National Institute of.
Creating Accessibility, Usability and Privacy Requirements for the Voluntary Voting System Guidelines (VVSG) Whitney Quesenbery TGDC Member Chair, Subcommittee.
TGDC Meeting, Jan 2011 Development of High Level Guidelines for UOCAVA voting systems Andrew Regenscheid National Institute of Standards and Technology.
TGDC Meeting, Jan 2011 Path Forward for FY11 UOCAVA Activities Nelson Hastings National Institute of Standards and Technology
Election Assistance Commission 1 Technical Guidelines Development Committee Meeting Post-HAVA Voting System Requirements – Federal Perspective February.
Briefing for the EAC Public Meeting Boston, Massachusetts April 26, 2005 Dr. Hratch Semerjian, Acting Director National Institute of Standards and Technology.
TGDC Pre-Meeting July , 2015 NIST Facility - Gaithersburg, Maryland Members : Designated Federal Official Matthew V. Masterson, EAC Commissioner,
Update: Revising the VVSG Structure Sharon Laskowski vote.nist.gov April 14, 2016 EAC Standards Board Meeting 1.
TGDC Meeting, Jan 2011 Report from Workshop on UOCAVA Remote Voting Systems Nelson Hastings National Institute of Standards and Technology
Interoperability Voting Public Work Group Jeramy Gray, CIO, LA County John Wack, NIST.
MOVE Act Overview Election Commissioners’ Association of Mississippi 2012 Annual Meeting Presented by: Liz Bolin Senior Attorney, Elections Division.
TGDC Meeting, Jan 2011 VVSG 2.0 and Beyond: Usability and Accessibility Issues, Gaps, and Performance Tests Sharon Laskowski, PhD National Institute of.
TGDC Meeting, Jan 2011 UOCAVA Pilot Projects for the 2012 Federal Election Report from the UOCAVA Working Group Andrew Regenscheid National Institute of.
TGDC Meeting, July 2011 VVSG 1.1 Test Suite Status Mary Brady Manager, NIST Information Systems Group, Software and Systems Division, ITL
The VVSG 2005 Revision Overview EAC Standards Board Meeting February 26-27, 2009 John P. Wack NIST Voting Program National Institute.
National Institute of Standards and Technology
Chapter 7: The Electoral Process Section 2
Chapter 7: The Electoral Process Section 2
Chapter 7: The Electoral Process Section 2
Presentation transcript:

NIST VOTING PROGRAM MARY BRADY, PROGRAM MANAGER

Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  Engage the Broader Community  Summary

Motivation: 2000 Presidential Election

Congressional Mandates HAVA 2002 (Public Law ) : The Help America Vote Act (HAVA) requires NIST/SSD to provide technical support for the development of Voluntary Voting Standard Guidelines (VVSG). Such technical work includes computer security, methods to detect and prevent fraud, protection of voter privacy, the role of human factors, including assistive technology for voters with disabilities, and remote access voting, including voting through the internet. MOVE 2009: The Military and Overseas Voters Empowerment Act of 2009 (MOVE) directs NIST and EAC to provide ”best practices or standards in accordance with electronic absentee voting guidelines established”… to support the pilot program or programs developed by DOD as directed by the Uniformed and Overseas Citizens Absentee Voting Act (UOCAVA) of 1986 as amended.

Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  NIST Response: A New Paradigm  Summary

Standards Development Accreditation, Testing, and Certification Usage by States Help America Vote Act

VVSG Development Voting Guidelines  VVSG  VVSG  VVSG Voting Guidelines  VVSG  VVSG  VVSG

Lab Accreditation, Testing, Certification VSTL’s – Voting System Test Laboratories are recommended for accreditation by NIST NVLAP Program. VSTL’s test voting systems and make recommendation to the EAC. - Certification - procedure by which a third party gives written assurance that a product, process or service conforms to specified requirements. EAC – Reviews testing information provided by the VSTL’s and certifies a system. Also responsible for decertifying a system if necessary. EAC – In consultation with NIST, may provide a request for interpretation.

TGDC Meeting July 20 – 21, 2015 Improving U.S. Voting Systems 9

Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  Engage the Broader Community  Summary

Presidential Commission on Election Administration Jurisdictions: Large and Small Equipment Changes Increasing Use of Information Technology in Elections Current Challenges

In Recent Years… No EAC Commissioners from 2011 until January 2015 TGDC has been on a hiatus Presidential Commission on Election Administration Voting Equipment is Changing Election officials looking to capitalize on advances in IT to gain efficiencies and lower cost Increasingly complex IT application Interconnected devices New paradigms for voting systems Voter Registration Ballot marking devices E-pollbooks Election Night Reporting

Presidential Commission on Election Administration (PCEA)

Basic Election Administration Facts 50 States 3,140 Counties 1,620 NE Townships 5,312 Midwest Townships 10,072 Election Jurisdictions Diversity is the underpinning of Elections. Source: Kim Brace

Range of Election Jurisdictions LA County Warehouse LA County 4.8 million registered voters 9 languages supported besides English (Spanish, Hindi, Japanese, Korean, Thai, Vietnamese, Chinese, Cambodian, Filipeno) 4,600 polling places 22,200 pollworkers LA County 4.8 million registered voters 9 languages supported besides English (Spanish, Hindi, Japanese, Korean, Thai, Vietnamese, Chinese, Cambodian, Filipeno) 4,600 polling places 22,200 pollworkers Source: Kim Brace

Voting Equipment is Changing 2010 & 2012 Source: Kim Brace

TGDC Meeting July 20 – 21, 2015 Improving U.S. Voting Systems 17

Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  Engage the Broader Community  Summary

Future of Voting – Feb 2013, 2015 NIST/EAC Symposiums Explore Emerging Trends in Voting

Standards Standards EffortsNIST Roadmap NASED Subcommittee EAC Future VVSG CSG Technology Group IEEE VSSC

NIST Roadmap: The Voter Journey Learn Do People Use Policy Preparing to vote Registration Forms/OVR Register to vote "My Voter" Portals Registrar Elections Web/Phone Am I/How do I register? What is on the ballot? Eligibility Voter Ed Choosing how to vote Request a VBM (or other) Access to 'Polling Place' What are my choices? Where do I go to vote "My Voter" Portals Online VBM SYstem Elections Web/Phone Elections office Voting Options Hours/Places Checking in/ getting ballot Poll workers Authenticate/ Sign-In Ballot Delivery System Transportation to Polls Receive 'ballot' How do I get my ballot Pollbook or Sign-in Voter ID Provisional Marking the ballot Poll workers Mark the ballot Ballot Ballot Marking System How do I mark as I intend? Activate or open the ballot Helper Rules Sample Ballots Pre-Marked Ballot Casting the ballot Poll workers Ballot Scanner Electronic Casting Cast the ballot Review the ballot How do I cast my ballot? Mail Ballot Return Counting Rules Helper Rules Verification & results Verify ballot was received See election results VBM/Ballot Tracking Elections Web/Phone E2E Verification System Who won? Did my vote count? Elections office Canvass Ballot Access

NIST Roadmap Partnered with Center for Civic Design Convened 2 Workshops Draft Report Available at:  Identified Six Priority Areas:  Support the design process  Engage voters effectively  Address the entire voter journey  Support evolving technology  Provide useful guidance and standards  Improve testing in design and certification

Principles High-level Discussion points U&A: 2 pages VVSG Additional Information U&A: 100 pages Test Assertions Low-level details U&A: 65 pages Encapsulate knowledge from other disciplines: U&A: >15 other standards activities NASED Subcommittee

TGDC Meeting July 20 – 21, 2015 Improving U.S. Voting Systems 25

IEEE Voting System Standards VSSC John Wack, Chair Election Results Reporting Sarah Whitt Election Data Modeling Kenneth Bennett Voting Methods Mathematical Models Lauren Massa- Lochridge Electronic Pollbooks Jay Bagga Event Logging John Wack “IEEE effort is most significant work going on in Voting” Matt Masterson EAC Commissioner “IEEE effort is most significant work going on in Voting” Matt Masterson EAC Commissioner

Trustworthy Elections Trustworthy Elections Legislatures, Election Officials Cybersecurity Education Risk-Based Security Manufacturers, Test Labs, EAC Software Assurance Test Assertions

Test Assertions: Low-level details NIST Team Draft from VVSG EAC/VSTL’s In-Depth Review Manufacturers Feedback Harmonized Assertions Usability/Accessibility (U/A) assertions Covered 19 sections: , TAs = (204 usability, 287 acc., 55 VVPAT Security assertions Covered Chapter 8, TAs Usability/Accessibility (U/A) assertions Covered 19 sections: , TAs = (204 usability, 287 acc., 55 VVPAT Security assertions Covered Chapter 8, TAs

Principle: No interference VVSG 1.0 Requirement c-iii: No voting equipment shall cause electromagnetic interference with assistive hearing devices that would substantially degrade the performance of those devices. The voting equipment, considered as a wireless device, shall achieve at least a category T4 rating as defined by American National Standard for Methods of Measurement of Compatibility between Devices and Hearing Aids, ANSI C TA3222ciii-1: Voting equipment, when used with assistive hearing devices, SHALL achieve at least a category T4 rating as defined by American National Standard for Methods of Measurement of Compatibility between Wireless Communications Devices and Hearing Aids, ANSI C TA3222ciii-1-1: Voting equipment, when used with cochlear implants, SHALL achieve at least a category T4 rating as defined by American National Standard for Methods of Measurement of Compatibility between Wireless Communications Devices and Hearing Aids, ANSI C TA3222ciii-1-2: Voting equipment, when used with hearing aids, SHALL achieve at least a category T4 rating as defined by American National Standard for Methods of Measurement of Compatibility between Wireless Communications Devices and Hearing Aids, ANSI C U&A: An Example

Voting Security Studies

CWE Mapping CWE Missing Authentication for Critical Function CWE Classic Buffer Overflow CWE Insufficiently Protected Credentials CWE Insufficient Verification of Data Authenticity CWE Missing Encryption of Sensitive Data CWE Uncontrolled Format String CWE Cryptographic Issues CWE Use of Insufficiently Random Values CWE Integer Overflow or Wraparound CWE-20 - Improper Input Validation CWE Use of Hard-coded Cryptographic Key CWE Use of a Broken or Risky Cryptographic Algorithm CWE Improper Privilege Management CWE Incorrect Implementation of Authentication Algorithm CWE Missing Authentication for Critical Function CWE Classic Buffer Overflow CWE Insufficiently Protected Credentials CWE Insufficient Verification of Data Authenticity CWE Missing Encryption of Sensitive Data CWE Uncontrolled Format String CWE Cryptographic Issues CWE Use of Insufficiently Random Values CWE Integer Overflow or Wraparound CWE-20 - Improper Input Validation CWE Use of Hard-coded Cryptographic Key CWE Use of a Broken or Risky Cryptographic Algorithm CWE Improper Privilege Management CWE Incorrect Implementation of Authentication Algorithm  Over 250 Vulnerabilities  Top 15 Voting CWE’s

Outline  Motivation & Congressional Mandates  Help America Vote Act  Current Challenges  Engage the Broader Community  Summary

Summary Elections are complex and the elections community is very diverse Wider engagement of state and local election officials, manufacturers, test laboratories, academics, and a number of advocacy groups Working with the broader elections community on laying the foundation for the next version of the VVSG Restarting the TGDC with recently appointed Commissioners Let’s get to work!