An Anonymous Voting Scheme based on Confirmation Numbers

Kazi Md. Rokibul Alam, Shinsuke Tamura, Shuji Taniguchi, Tatsuro Yanase · IEEJ Transactions on Electronics Information and Systems · 2010

This paper proposes a new electronic voting (e-voting) scheme that fulfills all the security requirements of e-voting i.e. privacy, accuracy, universal verifiability, fairness, receipt-freeness, incoercibility, dispute-freeness, robustness, practicality and scalability; usually some of which are found to be traded.When compared with other existing schemes, this scheme requires much more simple computations and weaker assumptions about trustworthiness of individual election authorities.Also in this scheme, the way of candidate selections is flexible; it accepts freely chosen write-in ballots, votes for a pre-specified or t out of l choices as well as yes/no votes.Still now, e-voting schemes have potential problems that may sacrifice all of their benefits (1) .Namely, simple vote verification mechanisms enable entities to link voters to their votes, and as a consequence, coercers can force voters to follow their intensions more easily.On the other hand, complicated mechanisms that achieve complete anonymity of voters while maintaining verifiability of their votes make e-voting systems non-scalable and non-practical.For example, many election schemes involve zero knowledge proof (ZKP) to achieve verifiability e.g. to confirm that only eligible votes are accepted and all eligible votes are counted, however ZKP requires complicated computations and communications which make e-voting schemes unrealistic.To overcome these difficulties, this paper proposes a mechanism based on confirmation numbers (CNs) involved in individual votes to make votes verifiable while disabling all entities including voters themselves to know the linkages between voters and their votes.Different from ZKP, a mechanism for CNs is simple enough, it requires much less computations for individual entities and thereby the scheme becomes scalable and practical.CNs are publicly disclosed and registered unique numbers, and they are generated as follows: To conceal C Cj (confirmation number assigned to voter V j ) from any entity including V j itself, firstly N unique numbers C 1 , C 2 , ---, C N (N is the number of voters) are generated as shown in Fig. 1 (a).Then P (at least 2) mutually independent election authorities TM 1 , ---, TM P repeatedly perform encryptions and shuffles of all CNs by using their secret encryption keys, i.e. firstly TM 1 encrypts C Cj to C Cj ' to be placed in random positions as shown in Fig. 1 (b).Then TM 2 , TM 3 ,--execute the same operations repeatedly, i.e.C Cj ' is converted to C Cj '', C Cj ''',---as shown in Fig. 1 (c) and (d)., which removes any link between C Cj and E(K * , C Cj ) unless all authorities (TMs) conspire.Therefore, when voters develop their votes by attaching CNs, any-one can confirm the accuracy of votes by checking if decrypted votes include registered CNs or not while disabling anyone even voters themselves to identify votes of individual voters.The entities involved in the scheme are N voters V j (j = 1, ---, N), Voting manager VM, P (at least 2) mutually independent Tallying managers TM i (i = 1, ---, P), Disruption detection manager DM and a set of public bulletin boards including VotingPanel and TallyingPanel that maintain authorized communication transcripts.The proposed voting scheme conducts elections through the following stages.Token acquisition: Anonymously authenticated voter V j picks unique token T tj while maintaining tokens collision free.Registration: Voter V j whose eligibility is checked by its identifier and password pair obtains blind signatures of all TMs on T tj i.e.S(X * , E(a j , T tj )), where a j is V j 's secret key.Therefore later on V j can prove its eligibility anonymously by showing S(X

Read the paper · More papers on PaperTik