Design and Implementation of a Web-Based Voting System Using E mail OTP Verification and Webcam Face Capture A Prototype for a Prime Ministerial Election Demonstration

Author

Smita Mangesh Junnarkar, Yadav Hari Haran Vellaisamy


Abstract

 Casting a vote from a phone or laptop is convenient, but that convenience is worthless if the system cannot tell who is voting or whether they have already voted. I built a small web-based voting system in Python using Flask, as a demonstration election where voters pick a Prime Minister from three candidates. The idea was simple: a voter signs up with their name and email, gets a six-digit OTP sent to that email, proves they actually own the inbox, takes a photo through their webcam, and only then can they cast one vote. The OTP is stored only as a keyed hash, expires after five minutes and locks after three wrong attempts. The vote is recorded through one atomic database operation so that a voter cannot be counted twice, and the table of votes holds no reference to the voter. The same code runs on SQLite during development and on PostgreSQL when deployed to a serverless platform. We checked the system with fourteen automated functional tests, all of which passed, and we are explicit about what those tests do not cover. The analysis is equally frank about the design itself: e-mail is a weak channel for OTPs, a photograph is evidence rather than identity verification, and the secrecy of the ballot depends on database design instead of cryptography. The system suits classroom, club or organisational elections and works as a teaching prototype. It is not suitable for statutory elections.



Keywords

online voting, one-time password, face capture, Flask, ballot secrecy, web security, serverless deployment



Full Text:

Download Paper PDF


References


[1] T. Kohno, A. Stubblefield, A. D. Rubin and D. S. Wallach, “Analysis of an electronic voting system,” in Proc. IEEE Symposium on Security and Privacy, 2004.

[2] D. Springall, T. Finkenauer, Z. Durumeric, J. Kitcat, H. Hursti, M. MacAlpine and J. A. Halderman, “Security analysis of the Estonian Internet voting system,” in Proc. ACM Conference on Computer and Communications Security (CCS), 2014.

[3] B. Adida, “Helios: Web-based open-audit voting,” in Proc. 17th USENIX Security Symposium, 2008.

[4] R. L. Rivest, “On the notion of ‘software independence’ in voting systems,” Philosophical Transactions of the Royal Society A, vol. 366, no. 1881, 2008.

[5] D. M’Raihi, M. Bellare, F. Hoornaert, D. Naccache and O. Ranen, “HOTP: An HMAC-based one-time password algorithm,” RFC 4226, IETF, 2005.

[6] D. M’Raihi, S. Machani, M. Pei and J. Rydell, “TOTP: Time-based one-time password algorithm,” RFC 6238, IETF, 2011.

[7] P. A. Grassi et al., “Digital identity guidelines: Authentication and lifecycle management,” NIST Special Publication 800-63B, 2017 (see section on out-of-band authenticators).

[8] Government of India, The Digital Personal Data Protection Act, 2023.

[9] Pallets Projects, “Flask documentation,” https://flask.palletsprojects.com.

[10] OWASP Foundation, “OWASP Top 10: 2021,” https://owasp.org/Top10/.

Note: references [9] and [10] informed implementation choices (session handling, input validation, and the classification of authentication and access-control failures) and are listed for completeness.

 

 

Share your valuable work from Social Media Buttons