Homomorphic Encryption Electronic Voting Method and System Based on a Decentralized Environment

A decentralized homomorphic encryption system with two-layer encryption and digital signatures secures and efficiently counts votes, addressing inefficiencies and security vulnerabilities in existing electronic voting systems.

CN116388953BActive Publication Date: 2025-07-15HENAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310112436.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-14
Publication Date
2025-07-15
Estimated Expiration
2043-02-14

AI Technical Summary

Technical Problem

The existing electronic voting scheme based on homomorphic encryption has inefficiency and security problems in multi-candidate voting and key security, and the voting results are prone to tampering, resulting in election failure.

Method used

The homomorphic encryption method in a decentralized environment is adopted to generate public and private key pairs through the key center, and the cloud vote counting center generates public and private keys, and the homomorphic encryption private keys and the cloud vote counting center are handed over to different candidates to hold. Voters perform ballot signatures and two-layer encryption, the cloud vote counting center performs decryption and homomorphic operations, and the public announcement center conducts results to ensure the security and fairness of the voting results.

Benefits of technology

The security and fairness of the voting results are achieved, the voting results are avoided in advance during the election process, the completeness and anonymity of the election are ensured, the computing efficiency is improved, and the multi-candidate voting and ballot testing is supported.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116388953B_ABST
    Figure CN116388953B_ABST
Patent Text Reader

Abstract

The present invention provides a homomorphic encryption electronic voting method and system based on a decentralized environment. This method first encrypts the ballot using the public key of homomorphic encryption, signs the ciphertext of the ballot after the first encryption using the private key of the voter, and then performs a second encryption on the signed ballot ciphertext using the public key of the cloud counting center. The private key of the cloud counting center and homomorphic decryption is held by different candidates. Due to the competitive relationship among different candidates, the security of the ballot result is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular, to a homomorphic encryption electronic voting method and system based on a decentralized environment. Background Art

[0002] Voting is an important way to ensure the fairness of elections. However, traditional voting schemes have significant security problems in ensuring the fairness of voting results. Due to advantages such as security and stability, electronic voting schemes have gradually received attention in recent years.

[0003] Current encryption electronic voting schemes can be classified according to their implementation methods into: electronic voting schemes based on a Mix-net, electronic voting schemes based on blind signatures, and electronic voting schemes based on homomorphic encryption. Among them, Mix-net is a routing protocol that enables untraceable communication through intermediate nodes. Each node receives messages from multiple senders to mix the messages of multiple users and sends the mixed messages to the next node. Therefore, it is difficult for eavesdroppers to trace end-to-end communication, thus achieving anonymous communication and protecting the privacy of voters. However, this scheme has instability. If any node fails, the entire voting activity will be disrupted. The concept of blind signature was first proposed in 1982. It is a two-party interactive protocol for protecting user privacy. The voter first blinds the original message and then sends it to a trusted third-party institution; the third-party institution signs it without being able to access the message content and returns it to the voter; finally, the user obtains the correct signature of the third-party institution on the original message after removing the blinding. However, electronic voting schemes based on blind signatures require anonymous channels to transmit ballots, but it is difficult to achieve completely anonymous channels in reality. Therefore, electronic voting schemes based on blind signatures are not widely used at present. Homomorphic encryption was proposed in 1978, and its basic idea is to directly integrate and calculate encrypted messages without decryption. When applied to electronic voting, the characteristics of homomorphic encryption ensure the confidentiality of intermediate voting results and greatly improve the credibility of the final voting results. Electronic voting schemes based on homomorphic encryption have been widely applied due to their stable and secure characteristics. This scheme can be classified into the ElGamal scheme, homomorphic schemes over integers, and schemes based on LWE / RLWE according to different homomorphic encryption methods.

[0004] However, most of the above solutions fail to achieve multi-candidate voting. Among them, although the Elgamal scheme achieves multi-candidate voting, the ElGamal algorithm uses multiplication both in the process of homomorphic encryption and decryption of plaintext. In practical applications, the number of votes is often huge. The decryption and encryption processes of the ElGamla algorithm for votes require a large number of exponentiation operations, so the computational efficiency is low, which will incur a significant time overhead and sometimes even affect the progress of the election. The LWE / RLWE scheme achieves multi-candidate voting through multiple voting keys, which is equivalent to conducting multiple votes, so the running efficiency of this scheme is not high. In addition, in practical applications, the security of the keys and the time control of the voting results are also problems that most homomorphic encryption-based electronic voting mechanisms have not been able to solve. To avoid the leakage of voting results before the end of the election, Braunlich et al. proposed an electronic voting scheme that combines the Paillier-based homomorphic encryption algorithm with the idea of threshold key sharing. This scheme uses the shamir secret sharing mechanism to divide the homomorphic private key into several shards and then distributes these shards to different candidates to ensure that the election results can be decrypted only when the specified time is reached. However, the shamir mechanism makes this scheme lack the security that an electronic voting scheme should have. Under the condition of sufficient computing power, an attacker can reconstruct the shards into a complete private key through a limited number of operations, which will lead to the failure of the entire election. Summary of the Invention

[0005] Aiming at the security problem of electronic voting caused by malicious voting of voters or attackers tampering with votes, the present invention provides a homomorphic encryption electronic voting method and system based on a decentralized environment.

[0006] On the one hand, the present invention provides a homomorphic encryption electronic voting method based on a decentralized environment, including:

[0007] Initialization stage:

[0008] The key center generates a pair of public and private keys for homomorphic encryption (HE pub , HE priv );

[0009] The cloud counting center generates a pair of public and private keys for the cloud counting center (CC pub , CC priv );

[0010] The homomorphic encryption private key HE priv and the private key CC priv of the cloud counting center are held by different candidates, ensuring that the same candidate cannot hold both private keys at the same time;

[0011] Identity authentication stage:

[0012] Voters authenticate their identities at the certificate management agency. After passing the authentication, they obtain their own public-private key pairs (u pub , u priv ) and trusted certificates;

[0013] Before voting, the certificate management agency pre-sends the trusted certificates of the voters to the cloud counting center;

[0014] Voting stage:

[0015] Voters use the public key HE pub of homomorphic encryption to encrypt the ballot to obtain the ciphertext of the ballot, and use their own private key u priv to sign the ciphertext of the ballot. Then use the public key CC pub of the cloud counting center to encrypt the signed ciphertext of the ballot again, and then send the re-encrypted ciphertext of the ballot and their own public key u pub to the cloud counting center;

[0016] After receiving the ciphertext of the ballot, the cloud counting center decrypts the ciphertext of the ballot using the private key CC priv of the cloud counting center, and uses the public key u pub of the voter to confirm the signature of the ciphertext of the ballot. After confirmation, perform a homomorphic operation on the ciphertext of the ballot and the previous voting results to update the voting results;

[0017] After all voters have voted, the cloud counting center sends the final voting results to the publicity center;

[0018] Result publicity stage:

[0019] The organization responsible for managing the key center uses the private key HE priv of homomorphic encryption to decrypt the final voting results, and the publicity center publicizes the decrypted final voting results.

[0020] Furthermore, in the initialization stage, the key center generates a public-private key pair (HE pub , HE priv ) for homomorphic encryption, which specifically includes:

[0021] Randomly select two large prime numbers p and q, satisfying gcd(pq, (p - 1)(q - 1)) = 1; where gcd is a function to find the greatest common divisor of two numbers;

[0022] Calculate the intermediate parameter n = pq and the intermediate parameter λ = lcm(p - 1, q - 1); where lcm is a function to find the least common multiple of two numbers;

[0023] Select a random large integer Calculate the intermediate parameter μ = [L(g λ mod n2 )] -1 mod n, to obtain the public key HE for homomorphic encryption pub =(n, g) and the private key HE priv =(λ, μ), where

[0024] Furthermore, in the initialization phase, the cloud vote-counting center generates the public and private key pair (CC pub , CC priv ) specifically including:

[0025] Randomly select a generator g1, and use g1 to generate a cyclic group G of order q1;

[0026] Randomly select an intermediate parameter x in G, where 1 < x < q1 - 1;

[0027] Calculate h = g1 x , to obtain the public key CC pub =(q1, g1, h) and the private key CC priv =x.

[0028] Furthermore, in the identity authentication phase, the generation process of the public and private key pair of the voter specifically includes:

[0029] Select two large prime numbers p2 and q2, and calculate the intermediate parameter n2 = p2q2;

[0030] Calculate φ(n2) = (p2 - 1)·(q2 - 1); where φ is the Euler's totient function;

[0031] Randomly select an intermediate parameter e, satisfying 0 < e < φ(n2) and gcd(e, φ(n2)) = 1; where gcd is the function to find the greatest common divisor of two numbers;

[0032] Calculate d = e -1 mod φ(n2), to obtain the public key u pub =(n2, e) and the private key u priv =(p2, q2, d).

[0033] Furthermore, in the voting phase, the voter uses the public key HE of homomorphic encryption pub to encrypt the ballot specifically including:

[0034] Record the ballot of voter i as m i , and map m i to x, where x ∈ [0, n);

[0035] Select an intermediate parameter satisfying gcd(r i , n) = 1;

[0036] Calculate m i ciphertext of

[0037] Furthermore, in the voting stage, the voter uses his own private key u priv to sign the ballot ciphertext, which specifically includes:

[0038] Generate a digital signature according to the voter's private key u priv to obtain the signed ballot ciphertext c =(c t_i ', s); where c i ' represents the ballot ciphertext obtained by voter i encrypting the ballot with the public key HE of homomorphic encryption i pub pub

[0039] Furthermore, in the voting stage, use the public key vc of the cloud counting center pub to re-encrypt the signed ballot ciphertext, which specifically includes:

[0040] Randomly select an intermediate parameter y, where 1 < y < q1 - 1;

[0041] Calculate the intermediate parameter a = g1 y and the intermediate parameter s1 = h y ;

[0042] Map c t_i to an element c t_i ' on G;

[0043] Calculate the intermediate parameter b = c t_i 's1, to obtain the ballot ciphertext C = (a, b), and send C to the cloud counting center.

[0044] Furthermore, in the voting stage, use the private key CC of the cloud counting center priv to decrypt the ballot ciphertext, which specifically includes:

[0045] Calculate b(a -1 ) x = c t_i 'h y (g1 xy ) -1 = c t_i 'g1 xy (g1 xy ) -1 = c t_i ';

[0046] Remap c t_i ' to c t_i =(c​i ,s).

[0047] Furthermore, in the voting stage, the public key u of the voter is used pub The specific steps for confirming the signature of the ballot ciphertext include:

[0048] Calculate c i ”≡s e mod n2;

[0049] If c i ”≡c i ' mod n2, then the signature is valid;

[0050] If c i ”≠c i ' mod n2, then the signature is invalid.

[0051] On the other hand, the present invention provides a homomorphic encryption electronic voting system based on a decentralized environment, including: a key generation center, a cloud vote counting center, voters, a certificate management agency, and a publicity center;

[0052] The key generation center is used to generate a pair of public and private keys for homomorphic encryption (HE pub , HE priv ) during the initialization stage;

[0053] The certificate management agency is used to authenticate the identity of the voter during the identity authentication stage, so that after the voter passes the identity authentication, the voter can obtain his own pair of public and private keys (u pub , u priv ) and a trusted certificate; and is used to send the voter's trusted certificate to the cloud vote counting center in advance before voting;

[0054] The cloud vote counting center is used to generate a pair of public and private keys for the cloud vote counting center (CC pub , CC priv ) during the initialization stage; during the voting stage, after receiving the ballot ciphertext, it uses the private key CC of the cloud vote counting center priv to decrypt the ballot ciphertext, uses the public key u of the voter pub to confirm the signature of the ballot ciphertext, and after the confirmation passes, performs a homomorphic operation on the ballot ciphertext and the previous voting result to update the voting result; and after all voters have voted, sends the final voting result to the publicity center;

[0055] The voter is used to encrypt the ballot using the public key HE for homomorphic encryption pub to obtain the ballot ciphertext, sign the ballot ciphertext using his own private key u priv , and use the public key CC of the cloud vote counting center pubRe-encrypt the signed ballot ciphertext, and then send the re-encrypted ballot ciphertext and its own public key u pub to the cloud voting center;

[0056] The publicity center is used in the result publicity stage when the organization responsible for managing the key center uses the private key HE of the homomorphic encryption priv After decrypting the final voting result, publicize the decrypted final voting result.

[0057] Advantages of the present invention:

[0058] The present invention signs and encrypts the ballot twice. First, the ballot is homomorphically encrypted using the homomorphic public key. Then, the voter signs the ballot using his own private key. Finally, the ballot is encrypted using the public key of the voting center. By signing and encrypting the ballot twice, the security of the ballot during transmission and the establishment of the decentralization scheme are guaranteed. Moreover, the cloud voting center and the private key of the homomorphic encryption are held by different candidates respectively, which can ensure the fairness of the election voting result, and the probability of leaking the result in advance is extremely small, ensuring the completeness of the electronic voting scheme. Brief description of the drawings

[0059] Figure 1 It is a model diagram of the homomorphic encryption electronic voting method based on the decentralized environment provided by the embodiment of the present invention;

[0060] Figure 2 It is a schematic diagram of encryption, decryption and vote counting in the voting stage provided by the embodiment of the present invention;

[0061] Figure 3 It is a simulation example diagram of the actual scenario of the participants provided by the embodiment of the present invention. Detailed implementation manners

[0062] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0063] Embodiment 1

[0064] As Figure 1 shown, the embodiment of the present invention provides a homomorphic encryption electronic voting method based on a decentralized environment, including an initialization stage, an identity authentication stage, a voting stage and a result publicity stage;

[0065] Initialization stage:

[0066] The key center generates a public-private key pair for homomorphic encryption (HE pub , HE priv );

[0067] The cloud vote-counting center generates a public-private key pair for the cloud vote-counting center (CC pub , CC priv );

[0068] The private key HE of homomorphic encryption priv and the private key CC of the cloud vote-counting center priv are held by different candidates to ensure that the same candidate cannot hold both private keys at the same time;

[0069] Identity authentication phase:

[0070] Voters authenticate their identities at the certificate management agency. After passing the identity authentication, they obtain their own public-private key pair (u pub , u priv ) and a trusted certificate;

[0071] Before voting, the certificate management agency pre-sends the trusted certificates of the voters to the cloud vote-counting center;

[0072] Voting phase:

[0073] Voters use the public key HE of homomorphic encryption pub to encrypt the ballot to obtain the ciphertext of the ballot, use their own private key u priv to sign the ciphertext of the ballot, use the public key CC of the cloud vote-counting center pub to encrypt the signed ciphertext of the ballot again, and then send the re-encrypted ciphertext of the ballot and their own public key u pub to the cloud vote-counting center, as Figure 1 shown;

[0074] After receiving the ciphertext of the ballot, the cloud vote-counting center decrypts the ciphertext of the ballot using the private key CC of the cloud vote-counting center priv , verifies the signature of the ciphertext of the ballot using the public key u of the voter pub . After passing the verification, it performs a homomorphic operation on the ciphertext of the ballot and the previous voting results to update the voting results, as Figure 1 shown;

[0075] After all voters have finished voting (for example, if the voting end deadline has been reached, it can be considered that the voting has ended), the cloud vote-counting center sends the final voting results to the publicity center;

[0076] Result publicity phase:

[0077] The organization responsible for managing the key center uses the private key HE of homomorphic encryption privThe final voting results will be decrypted and the Publicity Center will publicly announce the decrypted final voting results.

[0078] The traditional electronic voting scheme based on homomorphic encryption is to send the ballot to the counting center after homomorphic encryption, and the voting results are uniformly disclosed after the election. The traditional scheme has the following problems, namely: in the intermediate process, the voting system is vulnerable to attack and it cannot be guaranteed that the homomorphic private key used for decryption can be known until the end. Once the homomorphic private key is known in advance, the election result will become unreliable and the entire election will fail. In order to prevent this phenomenon from happening, the electronic voting method based on homomorphic encryption in a decentralized environment provided by the embodiment of the present invention, after the ballot is homomorphically encrypted, the public key pair of the cloud counting center and the private key of the voter are introduced to sign and re-encrypt the ballot ciphertext (specifically: the ballot is encrypted for the first time using the public key of homomorphic encryption, the ballot ciphertext after the first encryption is signed using the private key of the voter, and the ballot ciphertext with the signature is encrypted for the second time using the public key of the cloud counting center), and the cloud counting center and the homomorphic decryption private key are held by different candidates. Since there is a competitive relationship between different candidates, the security of the ballot result is guaranteed. Furthermore, the voting results in the embodiment of the present invention are updated in real time based on the voting actions of each voter (rather than updating uniformly after all voters have voted), thereby enabling voters to vote while the counting center counts the votes, thus avoiding the delay problem of calculating the voting results after the voting ends.

[0079] Example 2

[0080] Based on the above embodiments, the embodiments of the present invention mainly provide different key generation methods and the process of encrypting and decrypting ballots based on the keys generated in the generation methods. This embodiment can further ensure the security of the entire electronic voting process. The specific steps are as follows:

[0081] Initialization phase:

[0082] (1) The key center generates a public-private key pair for homomorphic encryption (HE pub ,HE priv );

[0083] Specifically, randomly select two large prime numbers p and q, satisfying gcd(pq, (p-1)(q-1)) = 1; where gcd is a function for finding the greatest common factor of two numbers. Calculate the intermediate parameter n = pq and the intermediate parameter λ = lcm(p-1, q-1); where lcm is a function for finding the least common multiple of two numbers; select a random large integer , calculate the intermediate parameter μ=[L(g λ modn 2 )] -1mod n to obtain the public key HE for homomorphic encryption pub =(n, g) and the private key HE priv =(λ, μ), where

[0084] (2) The cloud vote-counting center generates the public and private key pairs of the cloud vote-counting center (CC pub , CC priv );

[0085] Specifically, randomly select a generator g1, and use g1 to generate a cyclic group G of order q1; randomly select an intermediate parameter x in G, where 1 < x < q1 - 1; calculate h = g1 x , to obtain the public key CC pub =(q1, g1, h) and the private key CC priv =x;

[0086] (3) Hand over the private key HE priv of the homomorphic encryption and the private key CC priv of the cloud vote-counting center to different candidates, ensuring that the same candidate cannot hold both private keys at the same time;

[0087] Identity authentication stage:

[0088] (1) The voter registers locally through the client, and then carries the registration information to the certificate management authority for identity verification. After passing the identity verification, the voter obtains his own public and private key pairs (u pub , u priv ) and a trusted certificate;

[0089] Specifically, the generation process of the voter's public and private key pairs specifically includes: select two large prime numbers p2 and q2, and calculate the intermediate parameter n2 = p2q2; calculate φ(n2) = (p2 - 1)·(q2 - 1); where φ is the Euler's totient function. Randomly select an intermediate parameter e, satisfying 0 < e < φ(n2) and gcd(e, φ(n2)) = 1; calculate d = e -1 mod φ(n2) to obtain the public key u pub =(n2, e) and the private key u priv =(p2, q2, d);

[0090] In addition, in this embodiment, the difference from the above-mentioned Embodiment 1 is that: this scheme also limits the registration method. By adopting local software registration, users do not need to go to the registration center for registration.

[0091] (2) Before voting, the certificate management authority pre-sends the voter's trusted certificate to the cloud vote-counting center;

[0092] Voting stage (in this stage, voter i is taken as an example for description):

[0093] (1) The voter uses the public key He of homomorphic encryption pub to encrypt the ballot to obtain the ciphertext of the ballot, and uses his own private key u priv to sign the ciphertext of the ballot, and uses the public key CC of the cloud counting center pub to encrypt the signed ciphertext of the ballot again, and then sends the re-encrypted ciphertext of the ballot and his own public key u pub to the cloud counting center;

[0094] Specifically, the voter uses the public key HE of homomorphic encryption pub to encrypt the ballot, which specifically includes: denoting the ballot of voter i as m i , mapping m i to x, where x ∈ [0, n); selecting an intermediate parameter r i ∈ Z * n , satisfying gcd(r i , n) = 1; calculating the ciphertext c i ' of m i ' = g mi r i n (mod n 2 );

[0095] The voter uses his own private key u priv to sign the ciphertext of the ballot, which specifically includes: generating a digital signature s = sig priv (c upriv ') ≡ (c i ') i mod n2, so as to obtain the signed ciphertext of the ballot c d = (c t_i ', s); where c i ' represents the ciphertext of the ballot obtained by the voter i using the public key HE of homomorphic encryption i to encrypt the ballot. pub

[0096] The voter uses the public key CC of the cloud counting center pub to encrypt the signed ciphertext of the ballot again, which specifically includes: randomly selecting an intermediate parameter y, where 1 < y < q1 - 1; calculating the intermediate parameter a = g1 y and the intermediate parameter s1 = h y ; mapping c t_i to an element c t_i ' on G; calculating the intermediate parameter b = c t_i ​'s1, obtain the ballot ciphertext C = (a, b), and send C to the cloud voting center.

[0097] (2) After receiving the ballot ciphertext, the cloud voting center marks the public key of the voter corresponding to the ballot ciphertext to ensure that the public key is used for the first time. If it is not used for the first time, the ballot ciphertext is invalidated and the subsequent steps are not executed; if it is used for the first time, then use the private key CC of the cloud voting center priv to decrypt the ballot ciphertext, and use the public key u of the voter pub to confirm the signature of the ballot ciphertext. After confirmation, perform a homomorphic operation on the ballot ciphertext and the previous voting result to update the voting result;

[0098] Specifically, use the private key CC of the cloud voting center priv The decryption of the ballot ciphertext specifically includes: calculating b(a -1 ) x = c t_i 'h y (g1 xy ) -1 = c t_i 'g1 xy (g1 xy ) -1 = c t_i '; remap c t_i ' to c t_i = (c i ', s);

[0099] Use the public key u of the voter pub to confirm the signature of the ballot ciphertext specifically includes: calculating c i ” ≡ s e mod n2; if c i ” ≡ c i ' mod n2, then the signature is valid; if c i ” ≠ c i ' mod n2, then the signature is invalid.

[0100] After confirmation, perform a homomorphic operation on the ballot ciphertext and the previous voting result to update the voting result, specifically including:

[0101] For ease of description, denote the previous voting result as c', the plaintext corresponding to c' as m, and the intermediate parameters involved as r; similarly, for c i ', its corresponding plaintext is m i , and the intermediate parameters involved are r i ; where, m i , m ∈ Z n ,

[0102] It can be understood from the above that there exists c i ' = E(m i , r i ), c' = E(m, r). In this way, the homomorphic operation is performed on the ciphertext of the ballot and the previous voting result, that is:

[0103]

[0104] That is to say, the updated

[0105] (3) The voting process and the voting result update process of other voters are the same as those of voter i, which will not be elaborated here;

[0106] (4) After all voters have finished voting, the cloud counting center sends the final voting result to the publicity center.

[0107] In this embodiment, the difference from the above Embodiment 1 is also that: in order to further ensure the fairness of voting, the cloud counting center also needs to mark the public key of the voter to ensure that the public key is used for the first time. As a preferred marking method, as follows: construct such a database in the cloud counting center. In this database, the fields include the encrypted ballot c' of the voter, the public key u of the voter pub and the flag bit. The flag bit takes 0 or 1 to indicate whether the corresponding public key has been used. If it has been used, it is marked as 1, otherwise it is 0.

[0108] Result publicity stage:

[0109] The organization responsible for managing the key center uses the private key HE of homomorphic encryption priv to decrypt the final voting result, and the publicity center publicizes the decrypted final voting result;

[0110] Specifically, for the ciphertext calculate to obtain the plaintext m:

[0111]

[0112] wherein,

[0113] Embodiments of the present invention are based on technologies such as the Paillier homomorphic encryption algorithm, RSA, and ElGamal asymmetric encryption algorithm. The encrypted ballot and the homomorphic decryption key are distributed to different candidates with opposing relationships, so as to ensure that no party can know the voting result in advance during the election process. By adopting a homomorphic encryption mechanism, this solution satisfies self-counting, enabling voters to vote while the vote-counting center counts the votes, avoiding the delay problem of calculating the voting result after the voting ends. The ballot is signed and encrypted in two layers to ensure that the condition of power decentralization can be established. First, the user casts their own ballot, then the ballot is homomorphically encrypted, and then the voter encrypts the ballot with their own private key. Finally, the public key of the vote-counting center is used to encrypt the ballot and its signature.

[0114] Embodiment 3

[0115] Corresponding to the above method, embodiments of the present invention provide a homomorphic encryption electronic voting system based on a power-decentralized environment, including a key generation center, a cloud vote-counting center, voters, a certificate management institution, and a publicity center. Among them, voters are the main body of the operation of this system. They need to pass identity authentication and vote independently according to their personal intentions. The cloud vote-counting center needs to decrypt the encrypted ballot and verify the signature, and also needs to perform homomorphic operations on the ciphertext to generate the public and private key pairs of the cloud vote-counting center. The certificate management institution judges the user's registration information and updates it, generates the user's public and private key pairs (u pub ,u priv ) and issues a trusted certificate to the user. The key center generates the public and private key pairs of homomorphic encryption (HE pub ,HE priv ). The publicity center decrypts the ciphertext c' with the private key HE priv to obtain the plaintext m and finally conducts publicity. Specifically as follows:

[0116] The key generation center is used to generate the public and private key pairs of homomorphic encryption (HE pub ,HE priv ) in the initialization stage;

[0117] The certificate management institution is used to authenticate the voters during the identity authentication stage, so that after the voters pass the identity authentication, they can obtain their own public and private key pairs (u pub ,u priv ) and trusted certificates; and is used to send the trusted certificates of the voters to the cloud vote-counting center in advance before voting;

[0118] The cloud vote-counting center is used to generate the public and private key pairs of the cloud vote-counting center (CC pub ,CC priv ) in the initialization stage; in the voting stage, after receiving the ballot ciphertext, the private key CC of the cloud vote-counting center is usedpriv Decrypt the ballot ciphertext using the voter's public key u pub Verify the signature of the ballot ciphertext. After verification, perform a homomorphic operation on the ballot ciphertext and the previous voting results to update the voting results; and after all voters have voted, send the final voting results to the publicity center;

[0119] Voter, used to use the public key HE of homomorphic encryption during the voting phase pub Encrypt the ballot to obtain the ballot ciphertext using the voter's own private key u priv Sign the ballot ciphertext using the public key CC of the cloud counting center pub Re-encrypt the ballot ciphertext with the signature, and then send the re-encrypted ballot ciphertext and the voter's own public key u pub to the cloud counting center;

[0120] Publicity center, used to decrypt the final voting results using the private key HE of homomorphic encryption by the organization responsible for managing the key center during the result publicity phase priv After decrypting the final voting results, publicize the decrypted final voting results.

[0121] It should be noted that the system provided in the embodiments of the present invention is to implement the above method embodiments, and its functions can be specifically referred to the above method embodiments, which will not be elaborated here.

[0122] Embodiment 4

[0123] To verify the security of the present invention, the following security proof process is given in this embodiment.

[0124] (1) Security model

[0125] Assume that the selected third-party certification center (i.e., the certificate management agency) is "honest but curious": this third-party certification center will perform its duties according to the election rules, will not allow malicious attackers to pass the certification, and at the same time, will speculate on potential semi-malicious attackers based on its own analysis to prevent illegal voters from leaking election information and interfering with the election results. Assume that different candidates participating in the election are in an adversarial relationship and there is no cooperation between them. In addition, in the election activity, we believe that the cloud counting center is absolutely secure.

[0126] (2) Attack model

[0127] The attacker model can be divided into a semi - honest attacker model and a malicious attacker model. In the semi - honest attacker model, the attacker reaches an agreement with the participants through means such as bribery and threat. This agreement stipulates that the participants will not withdraw before the end of the activity. During the activity, the participants can honestly send their calculation results, that is, ensure that they will not tamper with the final result of the activity. However, the participants must inform the attacker of all relevant information about the entire activity, including historical communication information, calculation results, etc. In the malicious attacker model, the participants who reach an agreement with the attacker will no longer participate in the activity honestly and will send false results during the activity to achieve the purpose of tampering with the activity result.

[0128] (3) Security proof

[0129] The following conducts a security analysis on the potential threats that the electronic voting scheme proposed in this paper may encounter to prove the security of this scheme in relevant application scenarios.

[0130] Theorem 1 Only authenticated voters can vote.

[0131] Proof. In the registration phase, the voter must present his personal identity information to the trusted registration center and only after successful authentication can he obtain his personal public - private key pair. Moreover, only after the authentication center successfully verifies the authenticity of the personal information will the voter obtain his authentication certificate. Otherwise, the public - private key pair obtained during the registration phase is invalid. After successful authentication, the authentication center synchronizes the voter's public key to the cloud counting center. In the voting phase, in addition to selecting their target candidate, the voter also needs to input his public key. If the voter's identity is illegal, his public key is invalid and he cannot participate in the voting. The theorem is proved. Among them, the registration center and the authentication center both belong to the certificate management institution.

[0132] Theorem 2 In this scheme, the result of the election vote is fair, and the probability of leaking the result in advance is extremely small, ensuring the completeness of the electronic voting scheme.

[0133] Proof. In this scheme, the cloud counting center and the private key of the homomorphic encryption are held by different candidates respectively. Since there is an adversarial relationship between different candidates and there is no collusion situation, for the candidate holding the private key, without obtaining the private key of the cloud counting center, he cannot obtain the votes and thus cannot know the voting result; for the candidate holding the private key of the cloud counting center, because he does not obtain the homomorphic encryption private key and the probability of cracking the homomorphic encryption private key is negligible, he cannot know the voting result. The theorem is proved.

[0134] Theorem 3 After the voting ends, each voter can check whether his vote has been tampered with, ensuring the verifiability of the voting scheme.

[0135] Proof. After the voting ends, while the voting results are announced at the publicity center, the publicity center will also announce all the encrypted ballots and the private key CC of the counting center. priv Each voter can find their own ballot C = (a, b) according to their public key. The voter can use the private key CC of the counting center priv to decrypt the ciphertext and obtain c t_i =(c i ', s), so as to check whether their ballot has been tampered with before reaching the counting center. The theorem is proven.

[0136] Theorem 4 The electronic voting scheme implemented by this scheme will not disclose the privacy of voters and ensures the anonymity of the electronic scheme.

[0137] Proof. In the registration stage, this scheme uses local software for registration, and users do not need to go to the registration center for registration. In the voting stage, users do not need to present identity verification information involving personal privacy, and only need to present the public key obtained in the registration stage, so no personal information will be disclosed. The theorem is proven.

[0138] Theorem 5 During the election process, each voter can only vote once, ensuring the uniqueness of the voting scheme.

[0139] Proof. We construct such a database in the counting center: in this database, the fields consist of the encrypted ballot c' of the voter, the public key u of the voter pub and a flag bit. The flag bit takes 0 or 1 to indicate whether the corresponding public key has been used. If it has been used, it is marked as 1. In the voting stage, the voter selects their target candidate and inputs their public key at the same time. When the voter's ballot and public key are sent to the counting center, if the public key is used for the first time, the voter's ballot is stored in the database, and then the flag bit is set to 1; if the public key is not used for the first time, this piece of data will not be stored in the database and will not participate in the homomorphic operation. The theorem is proven.

[0140] (4) Performance analysis

[0141] This subsection will analyze the running efficiency of the proposed scheme of the present invention. Since the time costs consumed by addition and multiplication operations can be ignored compared to the time cost required for exponentiation operations, we choose to use the time consumed by exponentiation operations in the voting scheme as the standard for measuring the performance of the voting scheme. We denote the time required for one exponentiation operation, the number of voters, and the number of candidates as Cost e 、N v and N c , respectively. All test operations are carried out in the following hardware environment: CPU: 12 th Gen Core(TM) i7-12700H, Memory: 16GB, 4800MHZ DDR5.

[0142] The Cost is obtained through testing with the gmpy2 python module. e = 0.0000005s. To more clearly count the time cost of the voting scheme, we summarize the time costs of different institutions in the entire election activity. However, since the public notice center only performs one exponentiation operation, the time required for it is ignored.

[0143] (4.1) Performance analysis of the voter client

[0144] In the voting stage, each voter needs to sign and encrypt the ballot twice: First, use the homomorphic encryption public key to encrypt the ballot. The homomorphic encryption algorithm selected in this scheme is the Paillier encryption algorithm, and one exponentiation operation is required during encryption. Then, the voter signs the ballot with their personal private key. We choose the RSA signature algorithm to sign the ballot, and one exponentiation operation is required during the signature process. Finally, encrypt the ballot with the public key of the vote-counting center. We choose the Elgamal algorithm to encrypt it, and this algorithm requires two exponentiation operations. Therefore, for each voter client, the time cost required in the voting stage: COST voter = 4 × Cost e × N c .

[0145] (4.2) Performance analysis of the vote-counting center

[0146] During the election process, the vote-counting center needs to decrypt the encrypted ballot and verify the signature. In addition, the vote-counting center also needs to perform homomorphic addition on the ciphertext. However, since homomorphic addition is essentially a large integer multiplication, the time consumed is extremely small compared to the exponentiation operation, so it can also be ignored. After analysis, it is known that the vote-counting center performs one exponentiation operation respectively when decrypting and verifying the signature of the ballot. Therefore, the time cost required for the vote-counting center to process one ballot: COST cc = 2 × Cost e × N c .

[0147] (4.3) Comparison of the time costs of the scheme

[0148] We assume that each voter only needs to cast one vote for their target candidate during the voting process and does not need to perform any operations on other candidates. When counting votes, the number of votes for the selected candidate increases by 1, and the number of votes for other unselected candidates remains unchanged. Based on this assumption, we obtain the time costs required for this scheme and Scheme [1] (FAN X Y, WU T, ZHENG Q H, et al. HSE-Voting: a secure high-efficiency electronic voting scheme based on homomorphic signcryption[J]. Future Generation Computer Systems, 2020, 111: 754-762.) and summarize them in Table 1:

[0149] Table 1 Comparison of Time Costs between This Scheme and Existing Schemes

[0150] solution time cost of each voter time cost of the vote-counting center this solution <![CDATA[4×Cost e ×N c > <![CDATA[2×Cost e ×N c ×N v > Solution [1] <![CDATA[9×Cost e ×N c > <![CDATA[6×Cost e ×N c ×N v +4×Cost e >

[0151] (4.4) Actual Scenario Simulation

[0152] We conducted five scenario simulations according to different numbers of voters (N v = 1000, 2000, 4000, 7000, 10000) and counted the time spent by the vote-counting center in processing all votes. In the simulation, we assumed that the number of candidates was 10, i.e., N c = 10, and each voter also only needed to vote for one candidate, Cost e = 0.00012s. The comparison results of the time spent on CC for the two schemes are as Figure 3 shown.

[0153] After verification, the actual time costs required for the two schemes are in line with the theoretical estimates of the time costs in Table 1. In the five scenario simulations, the time performance of the proposed scheme of the present invention is superior to that of Scheme [1] in all aspects. Compared with Scheme [1], the time performance of the proposed scheme of the present invention has increased by approximately 43.2%.

[0154] In summary, the present invention proposes an electronic voting scheme based on homomorphic encryption and decentralization. This scheme not only ensures the security of the voting results during the election process through the Paillier encryption algorithm and the decentralization scheme, but also avoids the tampering of votes during the transmission process by signing and two-layer encryption of the votes. In addition, the present invention also meets completeness, anonymity, self-counting, uniqueness, and supports multi-candidate elections and vote verification.

[0155] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A homomorphic encryption electronic voting method based on a decentralized environment, characterized in that, Including: Initialization stage: The key center generates a public-private key pair for homomorphic encryption (HE pub , HE priv ); The cloud vote-counting center generates the public and private key pairs of the cloud vote-counting center (CC pub , CC priv ); Give the private key HE of the homomorphic encryption priv and the private key CC of the cloud vote-counting center priv to different candidates, ensuring that the same candidate cannot hold both private keys at the same time; Identity authentication stage: Voters authenticate their identities at the certificate management agency. After successful authentication, they obtain their own public-private key pair (u pub , u priv ) and a trusted certificate; Before voting, the certificate management agency pre - sends the voters' trusted certificates to the cloud counting center; Voting stage: The voter uses the public key HE of homomorphic encryption pub to encrypt the ballot to obtain the ciphertext of the ballot, and uses his own private key u priv to sign the ciphertext of the ballot, and uses the public key CC of the cloud counting center pub to encrypt the signed ciphertext of the ballot again, and then sends the re-encrypted ciphertext of the ballot and his own public key u pub to the cloud counting center; After receiving the encrypted ballot, the cloud vote counting center uses the private key CC of the cloud vote counting center priv to decrypt the encrypted ballot and uses the public key u of the voter pub to confirm the signature of the encrypted ballot. After confirmation, perform a homomorphic operation on the encrypted ballot and the previous voting results to update the voting results; After all voters have voted, the cloud counting center sends the final voting result to the publicity center; Result publicity stage: The organization responsible for managing the key center adopts the private key HE of homomorphic encryption priv Decrypt the final voting result, and the publicity center will publicize the decrypted final voting result.

2. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 1, characterized in that In the initialization phase, the key center generates a public-private key pair for homomorphic encryption (HE pub , HE priv ), which specifically includes: Randomly select two large prime numbers p and q, satisfying gcd(pq, (p - 1)(q - 1)) = 1; where gcd is a function to find the greatest common divisor of two numbers; Calculate the intermediate parameter n = pq and the intermediate parameter λ = lcm(p - 1, q - 1); where lcm is a function to find the least common multiple of two numbers; Select a random large integer Calculate the intermediate parameter μ = [L(g λ mod n 2 )] -1 mod n to obtain the public key HE for homomorphic encryption pub =(n, g) and the private key HE priv =(λ, μ), where 3. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 1, wherein In the initialization phase, the cloud vote-counting center generates a public-private key pair for the cloud vote-counting center (CC pub , CC priv ). Specifically, it includes: Randomly select a generator g1, and use g1 to generate a cyclic group G of order q1; Randomly select an intermediate parameter x in G, where x satisfies 1 < x < q1 - 1; Calculate h = g1 x , and obtain the public key CC of the cloud vote-counting center pub =(q1, g1, h) and the private key CC priv = x 4. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 1, characterized in that In the identity authentication stage, the generation process of the voter's public - private key pair specifically includes: Select two large prime numbers p2 and q2, and calculate the intermediate parameter n2 = p2 * q2; Calculate φ(n2) = (p2 - 1)·(q2 - 1); where φ is the Euler's totient function; Randomly select an intermediate parameter e, satisfying 0 < e < φ(n2) and gcd(e, φ(n2)) = 1; where gcd is a function to find the greatest common divisor of two numbers; Calculate d = e -1 mod φ(n2), to obtain the public key u of the voter pub =(n2, e) and the private key u priv =(p2, q2, d).

5. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 2, wherein During the voting phase, the voter uses the public key HE of homomorphic encryption pub The specific steps for encrypting the ballot include: Denote the ballot of voter \(i\) as \(m\). i , map \(m\) i to \(x\), where \(x\in[0,n)\); Select the intermediate parameter Satisfy gcd(r i , n) = 1; Calculate m i ciphertext of 6. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 4, wherein In the voting phase, the voter uses their own private key u priv Signing the ballot ciphertext specifically includes: According to the private key u of the voter priv Generate a digital signature So as to obtain the encrypted ballot ciphertext c with a signature t_i =(c i ', s); where c i ' represents the encrypted ballot ciphertext obtained by voter i encrypting the ballot using the public key HE of homomorphic encryption pub ​ 7. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 6, wherein During the voting phase, the public key vc of the cloud voting center is used pub The re-encryption of the signed ballot ciphertext specifically includes: Randomly select an intermediate parameter y, where y satisfies 1 < y < q1 - 1; Calculate intermediate parameter a = g1 y and intermediate parameter s1 = h y ; Map c t_i to an element c t_i ' on G; Calculate the intermediate parameter b = c t_i 's1, obtain the ballot ciphertext C = (a, b), and send C to the cloud vote-counting center.

8. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 7, wherein In the voting stage, the private key CC of the cloud vote counting center is used priv The decryption of the ciphertext of the ballot specifically includes: Calculate b(a -1 ) x = c t_i 'h y (g1 xy ) -1 = c t_i 'g1 xy (g1 xy ) -1 = c t_i '; Remap c t_i ' to c t_i = (c i ', s).

9. The homomorphic encryption electronic voting method based on a decentralized environment according to claim 8, characterized in that In the voting stage, the public key u of the voter is used pub The confirmation signature of the ballot ciphertext specifically includes: Calculate c i ”≡s e mod n2; If c i ”≡c i 'mod n2, then the signature is valid; If c i ” ≠ c i ' mod n2, then the signature is invalid.

10. A homomorphic encryption electronic voting system based on a decentralized environment, characterized in that, Including: Key generation center, cloud counting center, voters, certificate management agency and publicity center; Key generation center, which is used to generate public and private key pairs for homomorphic encryption (HE pub , HE priv ) The certificate management agency is used to authenticate voters during the identity authentication phase, so that after the voters pass the identity authentication, they can obtain their own public-private key pair (u pub , u priv ) and a trusted certificate; And for pre - sending the voters' trusted certificates to the cloud counting center before voting; Cloud vote counting center, which is used to generate the public and private key pairs of the cloud vote counting center (CC pub , CC priv ) during the initialization phase; during the voting phase, after receiving the ciphertext of the ballot, it uses the private key CC of the cloud vote counting center priv to decrypt the ciphertext of the ballot, and uses the public key u of the voter pub to confirm the signature of the ciphertext of the ballot. After the confirmation passes, it performs a homomorphic operation on the ciphertext of the ballot and the previous voting results to update the voting results; And for sending the final voting result to the publicity center after all voters have voted; Voters, who use the public key HE of homomorphic encryption during the voting phase pub to encrypt the ballot to obtain the ciphertext of the ballot, and use their own private key u priv to sign the ciphertext of the ballot, and use the public key CC of the cloud counting center pub to re-encrypt the signed ciphertext of the ballot, and then send the re-encrypted ciphertext of the ballot and their own public key u pub to the cloud counting center; The publicity center is used in the result publicity stage when the organization responsible for managing the key center uses the private key HE of homomorphic encryption priv After decrypting the final voting result, the decrypted final voting result is publicized.