Files
govoplan-voting/docs/POLYAS_PROVIDER_PROFILE.md
T

81 lines
4.0 KiB
Markdown

# POLYAS provider profile
## Current integration position
POLYAS is the first external provider selected for high-assurance GovOPlaN
Voting. This is an integration decision, not a certification claim. Until a
contracted machine interface, sandbox, exact product/version binding, and
current certificate evidence are available, the integration remains
operator-assisted and must not advertise the `external_certified` assurance
profile.
The public POLYAS material documents the Online Voting Manager, spreadsheet
electoral-roll import, PDF/Excel result export, an election control portal,
verification tools, SecureLink, and an electoral-board interface. It does not
document a stable public API that is sufficient for an unattended GovOPlaN
provider. The initial integration therefore uses the existing external
provider contract as its target and keeps manual handoffs explicit:
1. GovOPlaN freezes the ballot definition and electorate hashes.
2. An authorized election officer creates and seals the corresponding POLYAS
election using a reviewed export.
3. GovOPlaN records the POLYAS project reference, exact product/profile, and
handoff evidence without storing voter credentials.
4. Voters enter the provider through its controlled launch or invitation path.
5. An authorized officer imports signed result and protocol artifacts.
6. GovOPlaN verifies the frozen binding, records aggregate results and evidence,
and retains certification, challenge, and annulment as separate actions.
Operator-assisted imports must be labelled as such. Browser automation or
screen scraping is not an acceptable production API.
## Provider information required
Before implementing unattended preparation, launch, status, or result
acquisition, obtain from POLYAS:
- the contracted API/protocol specification and versioning policy;
- sandbox credentials and representative test-election fixtures;
- supported ballot methods, weighting, voter groups, replacement, quorum, and
threshold semantics;
- idempotency, revision, sealing, cancellation, outcome-unknown, and retry
behavior;
- invitation and voter-authentication boundaries;
- signed result, archive, audit, and verification artifact formats;
- retention, deletion, subprocessor, location, incident, and DPA terms;
- product/version-specific Security Target, certificate, maintenance reports,
validity period, and evaluated configuration;
- recovery and continuity evidence for an election in progress.
Credentials belong in governed credential envelopes. Raw selections, voter
credentials, recovery codes, and private provider keys must never cross the
Voting provider boundary.
## Certification gate
The BSI certificate `BSI-DSZ-CC-0862-V2-2021` for POLYAS CORE 2.5.0, including
maintained versions described by its maintenance reports, was valid through
2026-06-24. As of 2026-08-04, that validity date has passed. A new election must
not be labelled `external_certified` from this historical certificate alone.
The adapter must expose a `VotingProviderAssuranceDeclaration`. The runtime
accepts `external_certified` only when the declaration pins:
- the exact provider and implementation contract;
- supported assurance profile and protocol version;
- certification authority and reference;
- an independently retrievable evidence reference;
- a current validity window.
The declaration is frozen with the ballot and revalidated before cast and
finalization. Expiry, revocation, provider replacement, protocol change, or
certificate substitution fails closed and requires explicit reconciliation.
Authoritative references:
- [BSI certificate record](https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Sonstiges/0862_0862V2.html)
- [BSI TR-03169](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03169/BSI-TR-03169.pdf)
- [POLYAS security overview](https://support.polyas.com/en/faqs/security/ensure-secure-voting/)
- [POLYAS election control portal](https://support.polyas.com/en/online-voting-manager/features/authentication/election-control-portal/)