E lectron ic V otin g in th e N etherlands: from early A d o p tio n to early A bolishm ent*
Wolter Pieters · 2009
A b s tr a c t. This paper discusses how electronic voting was implemented in practice in the Netherlands, which choices were made and how elec tronic voting was finally abolished. This history is presented in the con text of the requirements of the election process, as well as the technical options th at are available to increase the reliability and security of elec tronic voting. 1 In tro d u ctio n In information security research, electronic voting is considered a particularly interesting topic. This may be due to a num ber of reasons. First of all, elections usually have high media coverage, especially if something goes wrong. This makes it easy to explain the societal relevance of the research. Furtherm ore, electronic voting seems to have a unique combination of security requirements: voters need to be authenticated, results need to be verifiable, but it should not be possible to link a vote to a voter. The secret ballot requirement, in combination with the so-called Australian ballot, listing all candidates on a single sheet, was introduced in many countries in the 19th century (see e.g. [28, 35]). It is now seen as a cornerstone of election law and international treaties: w ithout the secret ballot, voters could be subject to all kinds of bribery and coercion, for it would be possible to observe the choices they would make in the election. Combined with the dem and th a t results be verifiable, this requires well-designed procedures. It turns out not to be easy to computerise the intuitive ballot box property th a t what goes in will also come out, unaltered and unlinkably, especially if it is not allowed to reveal the identity of the voter. Many electronic voting systems th a t have been deployed worldwide were not especially designed to meet the dem and of verifiability. Votes may indeed be stored such th a t they cannot be traced back to the voter, guaranteeing secrecy of the ballot, but at the same tim e it is not always possible to judge afterwards if a vote was cast by an eligible voter, or produced by software m alfunction or m a licious activities. Because they are generally newer and operate over an insecure * Published in: Foundations of Security Analysis and Design V: FOSAD 2007/2008/2009 Tutorial Lectures. Springer LNCS 5705, p. 121-144, 2009