VOTINGONTOSEC: A SECURITY ONTOLOGY FOR RISK MODELING IN ELECTRONIC VOTING SYSTEMS
DOI:
https://doi.org/10.37943/RPCC6318Keywords:
blockchain electronic voting , security ontology , risk modeling , ISO/IEC 27005 , Smart City , cryptographic protocols , OWLAbstract
Blockchain voting needs a security model for shared infrastructure, cryptographic tools, and election rules. General ontologies do not jointly cover its threats and standards-based risk assessment. This paper presents VotingOntoSec, an OWL ontology aligned with ISO/IEC 27005. It represents assets, threats, vulnerabilities, risks, and countermeasures, including Sybil and smart-contract attacks and cryptographic protections. Development in Protégé 5.6.1 was followed by graph-based structural tests, HermiT 1.4.3 reasoning, competency-question assessment, comparison with five representative ontologies, and a Smart City voting scenario. The ontology contains 118 classes, 16 object properties, and 9 data properties. Its class hierarchy has no cycles, and HermiT found all named classes satisfiable. A five-asset example illustrates traceability from a vulnerable asset through an exploiting threat to a suitable control. Expert-assigned likelihood and criticality estimates yield reproducible inherent and residual risk scores. In the illustrative calculation, the criticality-weighted system score decreases from 0.81 to 0.32 after applying modeled controls; rankings remain unchanged as the likelihood weight varies from 0.3 to 0.7. Among the compared models, VotingOntoSec uniquely combines voting-specific blockchain threats, cryptographic countermeasures, and ISO/IEC 27005-aligned risk analysis. The case includes voter data, the ledger, consensus nodes, a communication channel, and a voting device. Results help rank needed controls and show how risk may change as inputs or weights change. The numerical example is illustrative rather than an empirical performance evaluation. The ontology and scripts are available for independent verification and reuse. VotingOntoSec provides a new practical semantic basis for structured security assessment of decentralized voting systems at scale.
References
Darmawan, I. (2021). E-voting adoption in many countries: A literature review. Asian Journal of Comparative Politics, 6(4), 482–504. https://doi.org/10.1177/20578911211040584
Jayakumari, B., Sheeba, S. L., Eapen, M., Anbarasi, J., Ravi, V., Suganya, A., & Jawahar, M. (2024). E-voting system using cloud-based hybrid blockchain technology. Journal of Safety Science and Resilience, 5(1), 102-109. https://doi.org/10.1016/j.jnlssr.2024.01.002
Kiayias, A., Zacharias, T., & Zhang, B. (2015). End-to-end verifiable elections in the standard model. In E. Oswald & M. Fischlin (Eds.), Advances in Cryptology – EUROCRYPT 2015 (pp. 468-498). Springer. https://doi.org/10.1007/978-3-662-46803-6_16
International Organization for Standardization. (2022). ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks. ISO. https://www.iso.org/standard/80585.html.
Hajian Berenjestanaki, M., Barzegar, H. R., El Ioini, N., & Pahl, C. (2024). Blockchain-based e-voting systems: A technology review. Electronics, 13(1), 17. https://doi.org/10.3390/electronics13010017
Barelli, R., D'Onghia, M., & Longari, S. (2025). Towards secure electronic voting: A survey on e-voting systems and attacks. IEEE Access, 13, 89600-89626. https://doi.org/10.1109/ACCESS.2025.3569334
Ohize, H. O., Onumanyi, A. J., Umar, B. U., Ajao, L. A., Isah, R. O., Dogo, E. M., Nuhu, B. K., Olaniyi, O. M., Ambafi, J. G., Sheidu, V. B., & Ibrahim, M. M. (2025). Blockchain for securing electronic voting systems: A survey of architectures, trends, solutions, and challenges. Cluster Computing, 28(2), 132. https://doi.org/10.1007/s10586-024-04709-8
Joni, S. A., Rahat, R., Tasnin, N., Ghose, P., Uddin, M. A., & Ayoade, J. (2024). Hybrid-blockchain-based electronic voting machine system embedded with Deepface, sharding, and post-quantum techniques. Blockchains, 2(4), 366-423. https://doi.org/10.3390/blockchains2040017
Biloshchytskyi, A., Yedilkhan, D., Faizullin, A., Biloshchytska, S., Kuchanskyi, O., & Medetbek, A. (2025). Development of the architecture of a software and hardware complex for data collection and management of smart technologies. In 2025 IEEE 13th International Conference on Intelligent Data Acquisition and Advanced Computing Systems (IDAACS) (pp. 1-7). IEEE. https://doi.org/10.1109/IDAACS68557.2025.11322246
Omirgaliyev, R., Khamzina, A., Yedilkhan, D., Friedrich, D., & Zhakiyev, N. (2025). An advanced data analysis method using heating degree-days for estimating the efficiency of buildings in smart cities: A case study of Astana. Results in Engineering, 28, 107502. https://doi.org/10.1016/j.rineng.2025.107502
Wen, S.-F., & Katt, B. (2024). Ontology-based metrics computation for system security assurance evaluation. Journal of Applied Security Research, 19(2), 230–275. https://doi.org/10.1080/19361610.2022.2157190
El Marzak, Y., Moudoubah, L., Chahid, A., Faris, S., & Mansouri, K. (2026). Designing an ontology-based framework for ISO 27002-based information security risk management. Engineering, Technology & Applied Science Research, 16(1), 31741–31747. https://doi.org/10.48084/etasr.15794
Preuveneers, D., & Joosen, W. (2024). An ontology-based cybersecurity framework for AI-enabled systems and applications. Future Internet, 16(3), 69. https://doi.org/10.3390/fi16030069
Oliveira, Í., Sales, T. P., Almeida, J. P. A., Baratella, R., Fumagalli, M., & Guizzardi, G. (2024). Ontology-based security modeling in ArchiMate. Software and Systems Modeling, 23(4), 925–952. https://doi.org/10.1007/s10270-024-01149-1
Fenz, S., Plieschnegger, S., & Hobel, H. (2016). Mapping information security standard ISO 27002 to an ontological structure. Information & Computer Security, 24(5), 452–473. https://doi.org/10.1108/ICS-07-2015-0030
Wang, Z., Zhu, H., Liu, P., & Sun, L. (2021). Social engineering in cybersecurity: A domain ontology and knowledge graph application examples. Cybersecurity, 4, 31. https://doi.org/10.1186/s42400-021-00094-6
Wilson, R. S. I., Goonetillake, J. S., Indika, W. A., & Ginige, A. (2023). A conceptual model for ontology quality assessment: A systematic review. Semantic Web, 14(6), 1051–1097. https://doi.org/10.3233/SW-233393
Kitsios, F., Chatzidimitriou, E., & Kamariotou, M. (2023). The ISO/IEC 27001 information security management standard: How to extract value from data in the IT sector. Sustainability, 15(7), 5828. https://doi.org/10.3390/su15075828
Chen, Y. (2022). Information security management: Compliance challenges and new directions. Journal of Information Technology Case and Application Research, 24(4), 243–249. https://doi.org/10.1080/15228053.2022.2148979
Kezadri Hamiaz, M., & Driss, M. (2025). Ethereum smart contracts under scrutiny: A survey of security verification tools, techniques, and challenges. Computers, 14(6), 226. https://doi.org/10.3390/computers14060226
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.