Hi,
>The attached is [a very rough cut of] the security requirements for generic
>Vote and Ballot tokens.
Thanks for getting the ball rolling ;-)
>It doesn't mention the identification and audit - I don't consider them to
>really belong there, in the security section.
I'd have to disagree. If you don't think about the security/privacy
implications of providing, for example, audit trails now then it may
prove difficult to retrofit them later.
Also you say:
>Note. It SHALL be possible to encrypt only certain components of the
>complete vote structure, rather >than encrypting the whole lot.
And the same again with regards to ballots. I don't see what you're
trying to say/achieve by this because plainly the entire vote
structure could be encrypted with something like SSL or just a hand
rolled encryption solution. Please explain...
regards,
Jason
--
The FREE e-democracy project
----------------------------------------
http://www.free-project.org
----------------------------------------
secure, private and reliable Free Software