VOTINGONTOSEC: A SECURITY ONTOLOGY FOR RISK MODELING IN ELECTRONIC VOTING SYSTEMS

Authors

DOI:

https://doi.org/10.37943/RPCC6318

Keywords:

blockchain electronic voting , security ontology , risk modeling , ISO/IEC 27005 , Smart City , cryptographic protocols , OWL

Abstract

Blockchain voting needs a security model for shared infrastructure, cryptographic tools, and election rules. General ontologies do not jointly cover its threats and standards-based risk assessment. This paper presents VotingOntoSec, an OWL ontology aligned with ISO/IEC 27005. It represents assets, threats, vulnerabilities, risks, and countermeasures, including Sybil and smart-contract attacks and cryptographic protections. Development in Protégé 5.6.1 was followed by graph-based structural tests, HermiT 1.4.3 reasoning, competency-question assessment, comparison with five representative ontologies, and a Smart City voting scenario. The ontology contains 118 classes, 16 object properties, and 9 data properties. Its class hierarchy has no cycles, and HermiT found all named classes satisfiable. A five-asset example illustrates traceability from a vulnerable asset through an exploiting threat to a suitable control. Expert-assigned likelihood and criticality estimates yield reproducible inherent and residual risk scores. In the illustrative calculation, the criticality-weighted system score decreases from 0.81 to 0.32 after applying modeled controls; rankings remain unchanged as the likelihood weight varies from 0.3 to 0.7. Among the compared models, VotingOntoSec uniquely combines voting-specific blockchain threats, cryptographic countermeasures, and ISO/IEC 27005-aligned risk analysis. The case includes voter data, the ledger, consensus nodes, a communication channel, and a voting device. Results help rank needed controls and show how risk may change as inputs or weights change. The numerical example is illustrative rather than an empirical performance evaluation. The ontology and scripts are available for independent verification and reuse. VotingOntoSec provides a new practical semantic basis for structured security assessment of decentralized voting systems at scale.

Author Biographies

Tolegen Aidynov, L.N. Gumilyov Eurasian National University, Kazakhstan

PhD Student, Department of Information Security

Dina Satybaldina, L.N. Gumilyov Eurasian National University, Kazakhstan

Candidate of Physical and Mathematical Sciences, Professor, Head of the Research Institute of Information Security and Cryptology

Willian Dimitrov, University of Library Studies and Information Technologies

PhD, Professor, Department of Computer Science

References

Darmawan, I. (2021). E-voting adoption in many countries: A literature review. Asian Journal of Comparative Politics, 6(4), 482–504. https://doi.org/10.1177/20578911211040584

Jayakumari, B., Sheeba, S. L., Eapen, M., Anbarasi, J., Ravi, V., Suganya, A., & Jawahar, M. (2024). E-voting system using cloud-based hybrid blockchain technology. Journal of Safety Science and Resilience, 5(1), 102-109. https://doi.org/10.1016/j.jnlssr.2024.01.002

Kiayias, A., Zacharias, T., & Zhang, B. (2015). End-to-end verifiable elections in the standard model. In E. Oswald & M. Fischlin (Eds.), Advances in Cryptology – EUROCRYPT 2015 (pp. 468-498). Springer. https://doi.org/10.1007/978-3-662-46803-6_16

International Organization for Standardization. (2022). ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks. ISO. https://www.iso.org/standard/80585.html.

Hajian Berenjestanaki, M., Barzegar, H. R., El Ioini, N., & Pahl, C. (2024). Blockchain-based e-voting systems: A technology review. Electronics, 13(1), 17. https://doi.org/10.3390/electronics13010017

Barelli, R., D'Onghia, M., & Longari, S. (2025). Towards secure electronic voting: A survey on e-voting systems and attacks. IEEE Access, 13, 89600-89626. https://doi.org/10.1109/ACCESS.2025.3569334

Ohize, H. O., Onumanyi, A. J., Umar, B. U., Ajao, L. A., Isah, R. O., Dogo, E. M., Nuhu, B. K., Olaniyi, O. M., Ambafi, J. G., Sheidu, V. B., & Ibrahim, M. M. (2025). Blockchain for securing electronic voting systems: A survey of architectures, trends, solutions, and challenges. Cluster Computing, 28(2), 132. https://doi.org/10.1007/s10586-024-04709-8

Joni, S. A., Rahat, R., Tasnin, N., Ghose, P., Uddin, M. A., & Ayoade, J. (2024). Hybrid-blockchain-based electronic voting machine system embedded with Deepface, sharding, and post-quantum techniques. Blockchains, 2(4), 366-423. https://doi.org/10.3390/blockchains2040017

Biloshchytskyi, A., Yedilkhan, D., Faizullin, A., Biloshchytska, S., Kuchanskyi, O., & Medetbek, A. (2025). Development of the architecture of a software and hardware complex for data collection and management of smart technologies. In 2025 IEEE 13th International Conference on Intelligent Data Acquisition and Advanced Computing Systems (IDAACS) (pp. 1-7). IEEE. https://doi.org/10.1109/IDAACS68557.2025.11322246

Omirgaliyev, R., Khamzina, A., Yedilkhan, D., Friedrich, D., & Zhakiyev, N. (2025). An advanced data analysis method using heating degree-days for estimating the efficiency of buildings in smart cities: A case study of Astana. Results in Engineering, 28, 107502. https://doi.org/10.1016/j.rineng.2025.107502

Wen, S.-F., & Katt, B. (2024). Ontology-based metrics computation for system security assurance evaluation. Journal of Applied Security Research, 19(2), 230–275. https://doi.org/10.1080/19361610.2022.2157190

El Marzak, Y., Moudoubah, L., Chahid, A., Faris, S., & Mansouri, K. (2026). Designing an ontology-based framework for ISO 27002-based information security risk management. Engineering, Technology & Applied Science Research, 16(1), 31741–31747. https://doi.org/10.48084/etasr.15794

Preuveneers, D., & Joosen, W. (2024). An ontology-based cybersecurity framework for AI-enabled systems and applications. Future Internet, 16(3), 69. https://doi.org/10.3390/fi16030069

Oliveira, Í., Sales, T. P., Almeida, J. P. A., Baratella, R., Fumagalli, M., & Guizzardi, G. (2024). Ontology-based security modeling in ArchiMate. Software and Systems Modeling, 23(4), 925–952. https://doi.org/10.1007/s10270-024-01149-1

Fenz, S., Plieschnegger, S., & Hobel, H. (2016). Mapping information security standard ISO 27002 to an ontological structure. Information & Computer Security, 24(5), 452–473. https://doi.org/10.1108/ICS-07-2015-0030

Wang, Z., Zhu, H., Liu, P., & Sun, L. (2021). Social engineering in cybersecurity: A domain ontology and knowledge graph application examples. Cybersecurity, 4, 31. https://doi.org/10.1186/s42400-021-00094-6

Wilson, R. S. I., Goonetillake, J. S., Indika, W. A., & Ginige, A. (2023). A conceptual model for ontology quality assessment: A systematic review. Semantic Web, 14(6), 1051–1097. https://doi.org/10.3233/SW-233393

Kitsios, F., Chatzidimitriou, E., & Kamariotou, M. (2023). The ISO/IEC 27001 information security management standard: How to extract value from data in the IT sector. Sustainability, 15(7), 5828. https://doi.org/10.3390/su15075828

Chen, Y. (2022). Information security management: Compliance challenges and new directions. Journal of Information Technology Case and Application Research, 24(4), 243–249. https://doi.org/10.1080/15228053.2022.2148979

Kezadri Hamiaz, M., & Driss, M. (2025). Ethereum smart contracts under scrutiny: A survey of security verification tools, techniques, and challenges. Computers, 14(6), 226. https://doi.org/10.3390/computers14060226

Downloads

Published

2026-09-30

How to Cite

Aidynov, T., Satybaldina, D., & Dimitrov, W. (2026). VOTINGONTOSEC: A SECURITY ONTOLOGY FOR RISK MODELING IN ELECTRONIC VOTING SYSTEMS. Scientific Journal of Astana IT University, 27(3), 300–309. https://doi.org/10.37943/RPCC6318

Issue

Section

Cybersecurity