A method, device, storage medium and electronic device for electronic voting
By processing the masked voting results and initial label values, and combining secure multi-party computation and homomorphic commitment functions, the problems of voting privacy and result accuracy in electronic voting are solved, achieving privacy protection and accurate public verification of voting results.
Patent Information
- Application Number
- CN202311070364.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-23
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2043-08-23
AI Technical Summary
In the process of electronic voting, how to protect the privacy of voters and ensure the accuracy of vote counting results, especially how to achieve both privacy and accuracy of voting results in a multi-party computing environment.
The method of processing the voting results and initial label values by masking is adopted. The mask bit share is generated by the secure multi-party computation preprocessing function, and the label commitment value is generated by the vote counting tree and homomorphic commitment function. The results are then publicly verified and decrypted to determine the final voting result.
This ensures the accuracy and transparency of the vote count while protecting the privacy of voters, and ensures that the public verification process of the voting results aligns with the wishes of all voters.
Smart Images

Figure CN117218758B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present specification relates to the technical field of computer, and particularly relates to an electronic voting method and device, a storage medium and an electronic equipment. BACKGROUND
[0002] With the continuous development of science and technology, electronic voting is applied more and more widely. At present, in the voting process, a voter can determine a selected option as a voting result according to a voting option, and send the voting result to a vote counter. The vote counter determines a final voting result according to the voting result of each voter. For example, in the election process, the voting option can be agree or disagree, so the voting result determined by the voter according to the voting option can be one of agree and disagree, and the final voting result determined by the vote counter according to the voting result of each voter can be the number of agrees and the number of disagrees.
[0003] In addition, in order to protect the privacy of the voters and ensure that the voters can vote according to their true will, the privacy of the voting result of each voter must be ensured, that is, the voting result of the voter cannot be known by other voters and the vote counter except the voter himself. In addition, it is also necessary to ensure that the final voting result meets the will of each voter, that is, it is necessary to ensure the accuracy of the final voting result determined by the vote counter. Therefore, how to perform electronic voting is an important problem.
[0004] Based on this, the present specification provides an electronic voting method. SUMMARY
[0005] The present specification provides an electronic voting method, device, storage medium and electronic equipment to partially solve the above problems existing in the prior art.
[0006] The present specification adopts the following technical solutions:
[0007] The present specification provides an electronic voting method, which is applied to a vote counter, and the method comprises the following steps:
[0008] determining a mask voting result published by each voter, and receiving an initial label value corresponding to the mask voting result sent by the voter, wherein the mask voting result is a result obtained by processing a voting result by the voter according to a mask bit share, and the mask bit share is generated by the voter based on a secure multi-party computation preprocessing function;
[0009] According to the mask voting result and the initial label value, a vote counting tree is constructed in advance, the mask voting result is counted based on the vote counting tree, a mask counting result output by the vote counting tree is determined, and a first result and an intermediate label value output by each operation node are determined; wherein the vote counting tree comprises a plurality of operation nodes.
[0010] based on the homomorphic commitment function, generating a label commitment value of each intermediate label value, and publishing each first result and the label commitment value, so that each voter verifies the mask statistic result according to the first result and the label commitment value published by the tallying party;
[0011] when the mask statistic result verification passes, determining the mask bit share corresponding to the mask statistic result published by each voter;
[0012] decrypting the mask statistic result according to the mask bit share, determining a final voting result, and publishing the final voting result.
[0013] Optionally, the operation node includes a plurality of AND operation units;
[0014] publishing each first result and the label commitment value, specifically including:
[0015] for each AND operation unit, determining a mask voting result input into the AND operation unit, and based on a secure multi-party computation preprocessing function, determining a verifiable mask bit share input into the AND operation unit and a verifiable mask bit share output by the AND operation unit;
[0016] determining a verifiable check bit of the AND operation unit according to the determined verifiable mask bit share and the mask voting result;
[0017] determining a message authentication code of the AND operation unit according to the verifiable check bit, and based on the homomorphic commitment function, determining a commitment value of the message authentication code;
[0018] determining the sum of each commitment value as a commitment value aggregation value, and publishing the commitment value aggregation value, each first result and the label commitment value.
[0019] Optionally, decrypting the mask statistic result according to the mask bit share to determine a final voting result, specifically including:
[0020] determining a mask commitment value corresponding to the mask bit share published by each voter;
[0021] publicly verifying each mask bit share according to each mask commitment value;
[0022] when the mask bit share verification passes, decrypting the mask statistic result according to the mask bit share to determine a final voting result.
[0023] Optionally, the mask commitment value includes an original commitment value and other commitment values;
[0024] determining a mask commitment value corresponding to the mask bit share published by each of the voters, specifically comprising:
[0025] for each of the voters, determining a raw commitment value corresponding to the mask bit share published by the voter and other commitment values, wherein the raw commitment value is determined by the voter based on the mask bit share corresponding to the voter, and the other commitment values are determined by the voter based on the mask bit shares published by other voters;
[0026] performing public verification on the mask bit shares according to the mask commitment values, specifically comprising:
[0027] determining a sum of the raw commitment values as a first value, and determining a sum of the other commitment values as a second value;
[0028] when the first value is consistent with the second value, determining that the mask bit shares pass the verification.
[0029] The specification also provides a method of electronic voting, which is applied to a voter, and the method comprises:
[0030] determining a voting result according to a voting option, and generating a mask bit share by using a secure multi-party computation preprocessing function according to a topology structure of a vote counting tree constructed in advance by a vote counter;
[0031] processing the voting result according to the mask bit share, determining a mask voting result, publishing the mask voting result, and generating an initial label value corresponding to the mask voting result, and sending the initial label value to the vote counter, so that the vote counter counts the mask voting results according to the mask voting results published by each of the voters and the initial label value received, determines a mask counting result output by the vote counting tree based on the vote counting tree, determines a first result output by each operation node in the vote counting tree and an intermediate label value, determines a label commitment value according to each intermediate label value, and publishes each first result and the label commitment value;
[0032] determining each first result and the label commitment value published by the vote counter;
[0033] determining a label value output by each operation node in the vote counting tree according to the first results, and determining a verification commitment value of each label value according to a homomorphic commitment function, and publishing the verification commitment value;
[0034] performing public verification on the mask counting result according to the label commitment value and the verification commitment value;
[0035] When the verification of the mask statistic result passes, a mask bit share corresponding to the mask statistic result is determined and published, so that the vote tallying party decrypts the mask statistic result according to the mask bit share published by each vote party, determines a final vote result, and publishes the final vote result.
[0036] Optionally, the mask statistic result is publicly verified according to the label commitment value and the verification commitment value, and specifically includes:
[0037] The verification commitment value published by the other vote party is determined as an other verification commitment value.
[0038] The other verification commitment value and the verification commitment value are aggregated.
[0039] The mask statistic result is publicly verified according to the aggregated commitment value and the label commitment value.
[0040] Optionally, the operation node includes a plurality of AND operation units.
[0041] The mask statistic result is publicly verified according to the aggregated commitment value and the label commitment value, and specifically includes:
[0042] When the aggregated commitment value is consistent with the label commitment value, the mask vote result published by the other vote party is determined.
[0043] For each AND operation unit, according to each mask vote result and each first result, a mask vote result input into the AND operation unit is determined, and a verifiable mask bit share input into the AND operation unit and a verifiable mask bit share output by the AND operation unit are determined.
[0044] According to the determined verifiable mask bit share and the mask vote result, a verifiable check bit of the AND operation unit is determined.
[0045] According to the verifiable check bit, a message authentication code of the AND operation unit is determined, and a verification commitment value of the message authentication code is determined based on the homomorphic commitment function.
[0046] A sum of the verification commitment values of the message authentication codes is determined as a verification aggregation commitment value, and the verification aggregation commitment value is published.
[0047] The verification aggregation commitment value published by the vote tallying party is determined, and the mask statistic result is publicly verified according to the verification aggregation commitment value and the verification commitment value.
[0048] Optionally, the mask bit share corresponding to the mask statistic result is determined and published, and specifically includes:
[0049] determine the mask bit share corresponding to the mask statistic result published by the other voters, and determine other commitment values based on the homomorphic commitment function according to the mask bit share published by the other voters, and publish the mask bit share, the original commitment value and the other commitment values.
[0050] determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish the mask commitment value, so that the voters verify the mask bit share according to the mask commitment value published by the tallying party.
[0051] Optionally, the mask commitment value includes an original commitment value and other commitment values.
[0052] determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish the mask commitment value, so that the voters verify the mask bit share according to the mask commitment value published by the tallying party.
[0053] determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish the mask commitment value, so that the voters verify the mask bit share according to the mask commitment value published by the tallying party.
[0054] determine the mask bit share corresponding to the mask statistic result published by the other voters, and determine other commitment values based on the homomorphic commitment function according to the mask bit share published by the other voters, and publish the mask bit share, the original commitment value and the other commitment values.
[0055] The present specification provides an electronic voting device, which is applied to a tallying party, and the device comprises:
[0056] a first determination module configured to determine mask voting results published by voters, and receive initial label values corresponding to the mask voting results sent by the voters, wherein the mask voting result is a result obtained by processing a voting result by the voter according to a mask bit share, and the mask bit share is generated by the voter based on a secure multi-party computation preprocessing function;
[0057] a tallying module configured to determine a mask statistic result output by a tallying tree, and determine first results and intermediate label values output by operation nodes, by statistically processing the mask voting results based on the tallying tree according to the mask voting results and the initial label values, wherein the tallying tree comprises a plurality of operation nodes;
[0058] a publishing module configured to generate label commitment values of the intermediate label values based on a homomorphic commitment function, and publish the first results and the label commitment values, so that the voters verify the mask statistic result according to the first results and the label commitment values published by the tallying party.
[0059] a second determination module configured to determine a mask bit share corresponding to the mask statistic result published by the voters when the mask statistic result is verified.
[0060] A decryption module is configured to decrypt the mask statistical result according to the mask bit shares, determine a final voting result, and publish the final voting result.
[0061] The present specification also provides an electronic voting device applied to a voting party, the device comprising:
[0062] A generation module is configured to determine a voting result according to a voting option, and generate mask bit shares by using a secure multi-party computation preprocessing function according to a topology structure of a pre-constructed tally tree of a tally party;
[0063] A sending module is configured to process the voting result according to the mask bit shares, determine a mask voting result, and publish the mask voting result, and generate a label value corresponding to the mask voting result, and send the label value to the tally party, so that the tally party performs statistics on the mask voting result according to the mask voting result published by each voting party and the received label value, determines a mask statistical result output by the tally tree, determines a first result output by each operation node in the tally tree and an intermediate label value, determines a label commitment value according to each intermediate label value, and publishes each first result and the label commitment value;
[0064] A determination module is configured to determine each first result and the label commitment value published by the tally party;
[0065] A commitment module is configured to determine a label value output by each operation unit in the tally tree according to the first result, and determine a verification commitment value of each label value according to a homomorphic commitment function, and publish the verification commitment value;
[0066] A verification module is configured to publicly verify the mask statistical result according to the label commitment value and the verification commitment value;
[0067] A mask module is configured to determine mask bit shares corresponding to the mask statistical result when the mask statistical result passes the verification, and publish the mask bit shares, so that the tally party decrypts the mask statistical result according to the mask bit shares published by each voting party, determines a final voting result, and publishes the final voting result.
[0068] The present specification provides a computer readable storage medium, the storage medium storing a computer program, the computer program being executed by a processor to implement the electronic voting method.
[0069] The present specification provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor implementing the electronic voting method when executing the program.
[0070] The above at least one technical solution adopted by the specification can achieve the following beneficial effects:
[0071] The electronic voting method provided by the specification determines the mask voting results published by each voting party and receives the label values corresponding to the mask voting results sent by each voting party. Then, based on the pre-constructed voting tree, the mask voting results are counted according to the mask voting results and the initial label values, the mask counting results output by the voting tree are determined, and the first results and intermediate label values output by each operation node are determined. Then, based on the homomorphic commitment function, the label commitment values of each intermediate label value are generated, and each first result and label commitment value are published, so that each voting party can publicly verify the mask counting results according to each first result and label commitment value published by the voting party. Then, when the mask counting results are verified, the mask bit shares corresponding to the mask counting results published by each voting party are determined, the mask counting results are decrypted according to the mask bit shares, the final voting results are determined, and the final voting results are published.
[0072] As can be seen from the above method, when performing electronic voting, the mask voting results published by each voting party are determined, and the initial label values corresponding to the mask voting results sent by each voting party are received. The mask voting results are the results of the voting results processed by the voting party according to the mask bit shares, so that the privacy contained in the voting results of each voting party can be protected. Then, based on the pre-constructed voting tree, the mask voting results are counted according to the mask voting results and the initial label values, the mask counting results output by the voting tree are determined, and the first results and intermediate label values output by each operation node are determined. Then, based on the homomorphic commitment function, the label commitment values of each intermediate label value are generated, and each first result and label commitment value are published, so that each voting party can publicly verify the mask counting results according to each first result and label commitment value published by the voting party. Then, when the mask counting results are verified, the mask bit shares corresponding to the mask counting results published by each voting party are determined, the mask counting results are decrypted according to the mask bit shares, the final voting results are determined, and the final voting results are published, so that the voting party can verify the accuracy of the mask counting results, thereby ensuring the accuracy of the process of the voting party counting the voting results. When the mask counting results are verified, the mask counting results are decrypted using the mask bit shares, thereby ensuring the accuracy of the final voting results. BRIEF DESCRIPTION OF DRAWINGS
[0073] The drawings described herein are used to provide further understanding of the specification, and form a part of the specification. The illustrative embodiments of the specification and their descriptions serve to explain the specification, and do not constitute an improper limitation on the specification. In the drawings:
[0074] Figure 1 A flowchart of a method of electronic voting provided in the present specification;
[0075] Figure 2 A schematic diagram of a voting tree provided in the present specification;
[0076] Figure 3 A flowchart of another method of electronic voting provided in the present specification;
[0077] Figure 4 A structural diagram of an electronic voting device provided in the present specification;
[0078] Figure 5 A structural diagram of another electronic voting device provided in the present specification;
[0079] Figure 6 A structural diagram of an electronic device corresponding to Figure 1 provided in the present specification. DETAILED DESCRIPTION
[0080] In order to make the purposes, technical solutions and advantages of the present specification clearer, the technical solutions of the present specification will be described in detail below with reference to the embodiments of the present specification and the corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present specification, but not all the embodiments. Based on the embodiments in the present specification, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present specification.
[0081] The technical solutions provided by the embodiments of the present specification will be described in detail below with reference to the drawings.
[0082] Figure 1 A flowchart of a method of electronic voting provided in the present specification, comprising the following steps:
[0083] S100: determining a mask voting result published by each voting party, and receiving an initial label value corresponding to the mask voting result sent by each voting party, wherein the mask voting result is a result processed by the voting party on a voting result according to a mask bit share, and the mask bit share is generated by the voting party based on a secure multi-party computation preprocessing function.
[0084] In a voting scenario, a voter determines a selected option as a voting result according to a voting option, and informs a vote counter of the voting result, the vote counter determines a final voting result according to the voting result of each voter, and publishes the final voting result, and each voter can learn the final voting result. The voting scenario can be a scenario of voting for a candidate, or a scenario of voting for a candidate, and the present specification does not make specific limitations. In different voting scenarios, the voter, the vote counter, the voting option, and the voting result can be different. In an election scenario, the voter is a voter or a voting device used by the voter, the vote counter is a vote counter or a vote counting device used by the vote counter, and the voting option can be two options of agreeing to the election of a candidate and disagreeing to the election of the candidate. The voter can select one option from the two options as the voting result, and inform the vote counter, the vote counter determines the final voting result according to the voting result of each voter, and publishes the final voting result, the final voting result can be one of agreement or disagreement, and can also be the number of agreement and disagreement. Subsequently, it is determined whether the candidate is elected according to the final voting result.
[0085] In addition, in a scheme evaluation scenario, the voter can be a member of a department or a group or a voting device used by each member, the vote counter can be any member other than the department or the group or a device for counting votes, and the voting option can be a selected scheme passing and a selected scheme not passing. The selected scheme is a scheme proposed by a member of a department or a group for a certain business, such as a business scheme for a commodity. The voter can select one option from the two options as the voting result, and inform the vote counter, the vote counter determines the final voting result according to the voting result of each voter, and publishes the final voting result, the final voting result can be one of passing or not passing, and can also be the number of passing and not passing. Subsequently, it is determined whether the selected scheme is passed according to the final voting result, if the selected scheme is passed, the business can be performed according to the selected scheme subsequently, and if the selected scheme is not passed, the members of the group or the department need to propose a new scheme.
[0086] However, in the voting scenario, the privacy of the voter needs to be ensured, and the accuracy of the final voting result determined by the vote counter needs to be ensured. Based on this, the device for conducting electronic voting can determine the mask voting result published by each voter, and receive the initial tag value corresponding to the mask voting result sent by each voter. The device for conducting electronic voting can be a vote counter for counting the number of votes (i.e., the voting result of each voter), and the vote counter can be a system, a server, or an electronic device such as a desktop computer, a notebook computer, etc. For ease of description, the method of electronic voting provided in the present specification will be described below with the vote counter as the execution subject. The voter can be a voting device used by the voter, and the voting device can be a terminal, a server, a system, etc., which is not limited in the present specification. The mask voting result is the result of the voting result processed by the voter according to the mask bit share, which is generated by the voter based on a secure multi-party computation preprocessing function. The initial tag value corresponding to the mask voting result is a bit string randomly generated by the voter based on the mask voting result. The secure multi-party computation preprocessing function is a function in an existing secure multi-party computation library, which can generate global keys of each voter and the vote counter, mask bit shares of data input into each operation node in the vote counting tree, mask bit shares of data output from each operation node in the vote counting tree, message authentication codes of each mask bit share to be verified, and keys corresponding to each message authentication code based on the vote counting tree.
[0087] To ensure the privacy of the voter, that is, to ensure that the voting result of the voter is not disclosed, the voter can determine the voting result according to the voting options, and generate the mask bit share by using the secure multi-party computation preprocessing function based on the topology structure of the vote counting tree constructed by the vote counter in advance. Then, the voting result is encrypted by using the mask bit share to obtain the mask voting result, which is published. The initial tag value corresponding to the mask voting result is determined and sent to the vote counter. Subsequently, the vote counter can determine the mask voting result published by each voter, and receive the initial tag value corresponding to the mask voting result sent by each voter. The vote counter can publish the vote counting tree constructed in advance, so that each voter determines the mask bit share based on the topology structure of the vote counting tree published by the vote counter. The initial tag value can be a bit string randomly generated by the voter based on the mask voting result. When the bit value of the mask voting result is 0, the voter can randomly generate a bit string of K bits as the initial tag value. When the bit value of the mask voting result is 1, the voter can perform an exclusive OR operation on the bit string generated when the bit value is 0 and a global key stored in advance, and take the result of the exclusive OR operation as the initial tag value. K is a natural number, which can be set in advance. The global key can be generated by the voter in advance based on the secure multi-party computation preprocessing function.
[0088] S102: According to the voting results of the masks and the initial label values, the voting tree is pre-constructed, the voting results of the masks are counted, the mask counting result output by the voting tree is determined, and the first result output by each operation node and the intermediate label value are determined.
[0089] S104: Based on the homomorphic commitment function, the label commitment value of each intermediate label value is generated, and each first result and the label commitment value are published, so that each voter publicly verifies the mask counting result according to the first result and the label commitment value published by the vote counter.
[0090] The vote counter counts the voting results of the masks based on the pre-constructed voting tree according to the voting results of the masks and the initial label values, determines the mask counting result output by the voting tree, and determines the first result output by each operation node and the intermediate label value. Then, based on the homomorphic commitment function, the label commitment value of each intermediate label value is generated, and each first result and the label commitment value are published, so that each voter publicly verifies the mask counting result according to the first result and the label commitment value published by the vote counter.
[0091] Wherein, publishing each first result and the label commitment value is to publish each first result and the label commitment value to each voter and a third party, and the third party is a person or device other than the voter and the vote counter, such as in an election scenario, the third party can be a person or device other than the voter or the vote device, the candidate and the vote counter or the vote device. Since each first result and the label commitment value are publicly disclosed to all people or devices, in addition to the above-mentioned voting device which can verify the mask counting result, the third party can also verify the mask counting result, which is not limited in the present specification. The public verification in the following process also means that in addition to the voters and the vote counter, the third party can also verify.
[0092] The vote tree is pre-constructed by the vote counter based on the number of voters. The vote tree includes a plurality of operation nodes and leaf nodes, the leaf nodes in the vote tree represent the voting results of each voter, each leaf node represents the voting result of a voter, and the nodes other than the leaf nodes in the vote tree are operation nodes, which are used for exclusive or operation, and operation of input data of the operation node. The result output by the root node of the vote tree is the final voting result after counting the voting results of each voter. For the upstream node (i.e. operation node) of the leaf node in the vote tree, the voting results of two voters are input into the upstream node, but for the upstream node of the upstream node, four voting results can be input into the upstream node of the upstream node.
[0093] For example, as shown in FIG. 1, the vote tree is pre-constructed by the vote counter based on the number of voters, and the vote tree includes a plurality of operation nodes and leaf nodes. Figure 2As shown, Figure 2 This diagram illustrates a vote-counting tree provided in this specification. Assume there are n voters participating in the electronic vote, designated as voters D1 to Dn, with inputs v1 to vn for each voter. v1 to vn are considered leaf nodes of the vote-counting tree. Since the vote counting process can be expressed as v1 + v2 + v3 + v4 + ... + vn, or (v1 + v2) + (v3 + v4) + ... + (vn-1 + vn) = [(v1 + v2) + (v3 + v4)] + ... + (vn-1 + vn)], at the bottom layer of the vote-counting tree, every two leaf nodes serve as the input to their upstream nodes. For example, v1 and v2, as leaf nodes, serve as the input to their upstream nodes, which are called computation nodes. From the upstream nodes of the leaf nodes to the top layer of the vote-counting tree, the outputs of every two computation nodes serve as the inputs to their upstream nodes. Figure 2 Nodes marked with a "+" in the square box represent computation nodes in the vote counting tree. The number of computation bits for each node increases layer by layer. For an upstream computation node between two leaf nodes, the computation bit is 1 bit. For an upstream computation node of that node, the computation bit is 2 bits. The computation bit is increased layer by layer until the root computation node is reached. The result output by the root computation node is v1+v2+v3+v4+...+vn, and the number of computation bits for the root computation node is logn bits.
[0094] The aforementioned homomorphic commitment function is used to process label values, which can be done by adding a random factor to the label value. When generating label commitment values for each intermediate label value based on the homomorphic commitment function, the vote counter can determine the commitment value corresponding to each intermediate label value based on the homomorphic commitment function, and use the sum of all commitment values as the label commitment value. Alternatively, the vote counter can first determine the sum of all intermediate label values, and then, based on the homomorphic commitment function, determine that the commitment value of the sum of all intermediate label values is the label commitment value. The label commitment value is used by the voters to verify whether the label values output by all computing nodes or units are correct during the vote counter's statistical voting process. By verifying the accuracy of the label values, the vote counter determines whether the mask statistical results obtained based on the computing nodes or units are accurate.
[0095] Specifically, the tallying party determines the mask vote result and the label value input into each operation node in the tallying tree according to the mask vote results and the initial label values, determines the mask vote result output from the operation node according to the mask vote result input into the operation node, and takes the mask vote result as the first result; and determines the label value output from the operation node according to the label value input into the operation node, and takes the label value as an intermediate label value. Then, the mask vote result output from the operation node is taken as the mask vote result input into the next operation node of the operation node, and the label value output from the operation node is taken as the label value input into the next operation node of the operation node, until the mask vote result and the label value output from the last operation node are determined, and the mask vote result output from the last operation node is taken as the mask statistical result output from the tallying tree. Then, the tallying party generates the label commitment value of each intermediate label value based on the homomorphic commitment function, and publishes each first result and the label commitment value, so that each voter publicly verifies the mask statistical result according to each first result and the label commitment value published by the tallying party.
[0096] wherein the next operation node of the operation node is an operation node inputting the mask vote result and the label value output from the operation node, when determining the mask vote result and the label value input into the operation node, if the operation node is an upstream operation node of a leaf node in the tallying tree, the mask vote result and the label value input into the operation node are one of the mask vote results published by each voter and the initial label values received by the tallying party; if the operation node is not an upstream operation node of a leaf node in the tallying tree, the mask vote result and the label value input into the operation node are the mask vote result and the label value output from the last operation node of the operation node.
[0097] In the present specification, the operation node can include an XOR operation unit, one operation node can include one or more XOR operation units, and therefore when each operation node includes several XOR operation units, in the step S102, the tallying party can determine the mask vote result and the label value input into each XOR operation unit in each operation node of the tallying tree, and then determine the mask vote result and the label value output from each XOR operation unit in the operation node according to the mask vote result and the initial label value of each operation node. The determined mask vote result of each XOR operation unit is XORed to determine the mask vote result output from the XOR operation unit as the first result. The determined label value of each XOR operation unit is XORed to determine the label value output from the XOR operation unit as the intermediate label value. Then, the mask vote result output from the XOR operation unit is taken as the mask vote result input into the next XOR operation unit in the operation node, and the label value output from the XOR operation unit is taken as the label value input into the next XOR operation unit in the operation node, until the mask vote result and the label value output from the last XOR operation unit are determined. The mask vote result output from the last XOR operation unit is taken as the mask vote result output from the operation node, and the label value output from the last XOR operation unit is taken as the label value output from the operation node. Then, the mask vote result output from the operation node is taken as the mask vote result input into the next operation node in the tallying tree, and the label value output from the operation node is taken as the label value input into the next operation node in the tallying tree, until the mask vote result and the label value output from the last operation node are determined. The mask vote result output from the last operation node is taken as the mask vote result output from the tallying tree.
[0098] If the XOR operation unit is the first operation unit in the operation node, the mask vote result and the label value input into the XOR operation unit are the mask vote result and the label value input into the operation node. If the XOR operation unit is not the first operation unit in the operation node, the mask vote result and the label value input into the XOR operation unit are the mask vote result and the label value output from the previous XOR operation unit in the operation node.
[0099] In the present specification, an operation node can include one or more AND operation units, and each operation node can include one or more AND operation units. When each operation node includes a plurality of AND operation units, in step 102, the tallying party can determine the mask vote result input into each AND operation unit in each operation node of the tallying tree, and then determine the unit ciphertext corresponding to each AND operation unit according to the determined mask vote result. Then, the tallying party can determine the label value input into each AND operation unit, and determine the mask vote result and the label value output by each AND operation unit according to the determined label value and the unit ciphertext. The determined mask vote result is taken as the first result, and the determined label value is taken as the intermediate label value. The mask vote result output by each AND operation unit is taken as the mask vote result input into the next AND operation unit, and the label value output by each AND operation unit is taken as the label value input into the next AND operation unit, until the mask vote result and the label value output by the last AND operation unit are determined. The mask vote result output by the last AND operation unit is taken as the mask vote result output by the operation node, and the label value output by the last AND operation unit is taken as the label value output by the operation node. Then, the mask vote result output by each operation node is taken as the mask vote result input into the next operation node, and the label value output by each operation node is taken as the label value input into the next operation node, until the mask vote result and the label value output by the last operation node are determined. The mask vote result output by the last operation node is taken as the mask vote result output by the tallying tree.
[0100] When the AND operation unit is the first operation unit in the operation node, the mask vote result and the label value input into the AND operation unit are the mask vote result and the label value input into the operation node. When the AND operation unit is not the first operation unit in the operation node, the mask vote result and the label value input into the AND operation unit are the mask vote result and the label value output by the previous AND operation unit.
[0101] The unit ciphertexts are determined by each voter based on the tally tree and sent to the tally center. Therefore, in step S100, the tally center can send the pre-constructed tally tree to each voter, then determine the mask vote results published by each voter, and receive the initial tag values corresponding to the unit ciphertexts of each and operation unit and the mask vote results sent by each voter. Each voter can generate a corresponding unit ciphertext for each and operation unit in the tally tree, and when generating the unit ciphertext, the bit value of the input mask vote result of the and operation unit needs to be determined. The bit value can be 0 or 1. Since there are two mask vote results input into the and operation unit, there are four combinations of bit values of the mask data input into the and operation unit, i.e., 00, 01, 10, and 11. Each combination corresponds to a unit ciphertext. Therefore, the unit ciphertext corresponding to each and operation unit can be generated based on multiple combinations, and the unit ciphertext corresponding to each combination can be generated by each voter, i.e., there are several unit ciphertexts corresponding to the and operation unit.
[0102] Based on this, when determining the unit ciphertext corresponding to the and operation unit based on the determined mask vote result, the tally center can determine the combination of bit values corresponding to the mask vote result based on the determined mask vote result, and determine the unit ciphertext corresponding to the and operation unit from the unit ciphertexts of the and operation unit sent by each voter based on the determined combination, i.e., there are several unit ciphertexts corresponding to the and operation unit. For example, the voters D1 and D2 send four unit ciphertexts of the and operation unit A to the tally center, and the four unit ciphertexts are determined based on the four combinations (i.e., 00, 01, 10, and 11). Therefore, the tally center can receive a total of eight unit ciphertexts of the and operation unit A. Assuming that the bit values corresponding to the determined mask vote result are 0 and 1, respectively, the combination of bit values is 01, and the tally center can determine the unit ciphertext corresponding to the combination 01 from the eight unit ciphertexts of the and operation unit A sent by the voters D1 and D2. Therefore, the tally center can determine two unit ciphertexts corresponding to the and operation unit A, i.e., there are two unit ciphertexts corresponding to the and operation unit A.
[0103] When determining the mask data and tag value output by the and operation unit based on the determined tag value and unit ciphertext, the tally center can determine the mask vote result and tag value output by the and operation unit corresponding to each unit ciphertext based on the determined tag value and the unit ciphertext. Then, the determined mask vote results are taken as the mask vote results output by the and operation unit, and the determined tag values are taken as the tag values output by the and operation unit.
[0104] In the present specification, the operation node can also include several AND operation units and several XOR operation units. Therefore, in step S102, the tallying party can determine the type of each operation unit in each operation node in the tallying tree, and then determine the mask vote result and the label value output by the XOR operation unit according to the above process. When the operation unit is an XOR operation unit, the determined mask vote result is taken as the first result, and the determined label value is taken as the intermediate label value, which will not be described here. Then, the determined mask vote result and the label value are taken as the mask vote result and the label value of the next operation unit input into the XOR operation unit. When the operation unit is an AND operation unit, the mask vote result and the label value output by the AND operation unit are determined according to the above process, and the determined mask vote result is taken as the first result, and the determined label value is taken as the intermediate label value, which will not be described here. Then, the determined mask vote result and the label value are taken as the mask vote result and the label value of the next operation unit input into the AND operation unit. The subsequent process is similar to the process of determining the mask statistical result and the label commitment value, which will not be described here.
[0105] In addition, since the mask vote result output by the XOR operation unit can be obtained by performing XOR operation on the mask vote result input into the XOR operation unit, and the mask vote result of each voter is published, that is, each party can know the mask vote result of each voter, therefore, when verifying the mask statistical result, the tallying party can only take the determined mask vote result output by each AND operation unit as the first result, and take the label value output by each AND operation unit as the intermediate label value. Then, based on the homomorphic commitment function, the label commitment value of each intermediate label value is generated, and each first result and label commitment value is published.
[0106] S106: When the mask statistical result is verified, the mask bit share corresponding to the mask statistical result published by each voter is determined.
[0107] S108: According to the mask bit share, the mask statistical result is decrypted to determine the final vote result, and the final vote result is published.
[0108] When the mask statistical result is verified, the mask bit share corresponding to the mask statistical result published by each voter is determined. According to the mask bit share, the mask statistical result is decrypted to determine the final vote result, and the final vote result is published. Each voter sends the mask bit share corresponding to the mask statistical result to the tallying party, and the mask bit share is used to decrypt the mask statistical result output by the tallying tree.
[0109] Specifically, each voter verifies the mask statistic result according to the first result published by the tallying party in step S104 and the label commitment value. When the mask statistic result is verified, each voter publishes the mask bit share corresponding to the mask statistic result. The tallying party can determine the mask bit share published by each voter, decrypt the mask statistic result according to the mask bit share, determine the final voting result, and publish the final voting result. Each mask bit share is a key generated by the voter for the mask statistic result output by the tallying tree, and the tallying party can decrypt the mask statistic result output by the tallying tree according to the mask bit share.
[0110] In addition, in order to ensure the accuracy of the mask bit share published by each voter, the voter can determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish it. The tallying party determines the mask commitment value corresponding to the mask bit share published by each voter, and verifies the mask bit share according to the mask commitment value. When the mask bit share is verified, the final voting result is determined by decrypting the mask statistic result according to the mask bit share, and the final voting result is published.
[0111] The mask commitment value published by each voter includes an original commitment value and other commitment values, so when determining the mask commitment value corresponding to the mask bit share published by each voter, the tallying party can determine the original commitment value corresponding to the mask bit share published by each voter, and the other commitment values are determined by the other commitment values. The commitment value determined by the voter based on the mask bit share published by the other voter. The other voters are the voters other than the voter.
[0112] Based on this, when verifying the mask bit share according to the mask commitment value, the tallying party can determine that the sum of each original commitment value is a first value, and the sum of each other commitment value is a second value. When the first value is consistent with the second value, it is determined that the mask bit share is verified. When the first value is inconsistent with the second value, it is determined that the mask bit share is not verified, and the tallying party publishes a message indicating that the verification is not passed.
[0113] When decrypting the mask statistic result according to the mask bit share to determine the final voting result, the following formula can be used for calculation:
[0114]
[0115] wherein z w represents the final voting result, z′ w represents the mask statistic result, represents the exclusive or operation, represents each mask bit share sent by the voting party Di, and n represents the number of voting parties.
[0116] As can be seen from the above method, when performing electronic voting, the vote counter can determine the mask voting result published by each voting party and receive the initial label value corresponding to the mask voting result sent by each voting party. The mask voting result is the result after the voting result is processed by each voting party according to the mask bit share, so that the privacy contained in the voting result of each voting party can be protected. Then, according to each mask voting result and each initial label value, the mask voting result is counted based on the pre-constructed vote counting tree, the mask counting result of the vote counting tree is determined, and the first result and the intermediate label value output by each operation node are determined. Then, based on the homomorphic commitment function, the label commitment value of each intermediate label value is generated, and each first result and label commitment value is published, so that each voting party can verify the mask counting result according to the first result and label commitment value published by the vote counter, so as to ensure the accuracy of the process of counting the voting result by the vote counter, that is, to ensure the accuracy of the mask counting result determined by the vote counter. And the vote counter only knows the mask counting result, and does not know the specific voting result of each voting party, so the privacy of the voting party is protected. In addition, the calculation speed of the voting result is also accelerated, and the time cost is reduced. At the same time, when publicly verifying the mask counting result, third parties can also verify it, which better ensures the accuracy of the mask counting result. Then, when the mask counting result is verified, the mask bit share corresponding to the mask counting result published by each voting party is determined, and the mask counting result is decrypted according to each mask bit share, the final voting result is determined, and the final voting result is published, so that the vote counter uses each mask bit share to decrypt the mask counting result when the mask counting result is verified, and the accuracy of the final voting result is ensured.
[0117] Further, in order to ensure the accuracy of the mask bit share published by each voting party, the vote counter can also verify each mask bit share according to the mask commitment value corresponding to each mask bit share published by each voting party, and when each mask bit share is verified, the mask counting result is decrypted using each mask bit share to determine the final voting result and publish it. Avoiding the mask bit share published by each voting party is incorrect, ensures the accuracy of the final voting result determined.
[0118] In the present specification, in addition to determining whether the mask statistic result is accurate by verifying whether the label value is accurate, the mask statistic result can be further determined to be accurate by verifying the mask vote result output by the operation node or operation unit. Therefore, when the first result and the label commitment are published in step S104, the tallying party can further determine, for each and operation unit, the mask vote result input into the and operation unit, and determine the verifiable mask bit share input into the and operation unit and the verifiable mask bit share output by the and operation unit based on the secure multi-party computation preprocessing function. According to the determined verifiable mask bit share and the mask vote result, the verifiable check bit of the and operation unit is determined. According to the verifiable check bit, the message authentication code of the and operation unit is determined, and the authentication code commitment value of the message authentication code is determined based on the homomorphic commitment function. Then, the sum of the authentication code commitment values is determined as the authentication code aggregation commitment value, and the authentication code aggregation commitment value, the first result and the label commitment value are published. The verifiable mask bit share includes the mask bit share, the key of the message authentication code corresponding to the mask bit share and the key of the message authentication code corresponding to the mask bit share of the other voter, and the other voter is the voter other than the voter itself. The authentication code aggregation commitment value is used to publicly verify the accuracy of the mask vote result output by the operation node or operation unit by each voter.
[0119] When the verifiable check bit of the and operation unit is determined according to the determined verifiable mask bit share and the mask vote result, the following formula can be used for calculation:
[0120]
[0121]
[0122] wherein, and represent three parameters in the ternary group corresponding to the and operation unit determined by the tallying party T based on the secure multi-party computation preprocessing function, and the three parameters can be 0 or any three values.d γ and e γ may be any pre-set value or directly 0. represents the verifiable check bit of the and operation unit determined by the tallying party T, and z′ α and z′ β represent two mask vote results input into the and operation unit, and represent the verifiable mask bit share input into the and operation unit determined by the tallying party T, represents the verifiable mask bit share output by the and operation unit determined by the tallying party T.
[0123] Since the verifiable check bit is obtained by the above calculation, the verifiable check bit includes the message authentication code corresponding to the check bit, and the tallying party can directly determine the message authentication code of the AND operation unit from the verifiable check bit corresponding to the AND operation unit, that is, the message authentication code corresponding to the check bit. Subsequently, based on the homomorphic commitment function, the authentication code commitment value of the message authentication code is determined. Then, the sum of each authentication code commitment value is determined as the authentication code aggregation commitment value, which can be represented as wherein, represents the message authentication code of the AND operation unit determined by the tallying party T, W represents the set of AND operation units, and Com(x) represents the homomorphic commitment function.
[0124] In the step S102, the tallying party can determine the masked vote result output by the AND operation unit and the label value based on the determined label value and the unit ciphertext. For each unit ciphertext, the tallying party can determine the to-be-verified masked vote result output by the AND operation unit, the label value output by the AND operation unit, and the message authentication code output by the AND operation unit (i.e., the message authentication code corresponding to the to-be-verified masked vote result output by the AND operation unit) based on the determined label value and the unit ciphertext. Then, the key of the message authentication code output by the AND operation unit generated based on the secure multi-party computation preprocessing function is determined, and the first calculation result is determined by calculating based on the key and the to-be-verified masked vote result output by the AND operation unit. Then, it is determined whether the first calculation result is consistent with the message authentication code corresponding to the to-be-verified masked vote result (i.e., the message authentication code output by each AND operation unit). If yes, the to-be-verified masked vote result is taken as the masked vote result output by the AND operation unit. If no, the tallying party corresponding to the to-be-verified masked vote result that fails the verification is determined, and a message indicating that the verification fails is sent to the determined tallying party.
[0125] In the step S102, the tallying party can determine the masked vote result output by the AND operation unit and the label value based on the determined label value and the unit ciphertext. For each unit ciphertext, the tallying party can determine the to-be-verified masked vote result output by the AND operation unit, the label value output by the AND operation unit, and the message authentication code output by the AND operation unit (i.e., the message authentication code corresponding to the to-be-verified masked vote result output by the AND operation unit) based on the determined label value and the unit ciphertext. Then, the key of the message authentication code output by the AND operation unit generated based on the secure multi-party computation preprocessing function is determined, and the first calculation result is determined by calculating based on the key and the to-be-verified masked vote result output by the AND operation unit. Then, it is determined whether the first calculation result is consistent with the message authentication code corresponding to the to-be-verified masked vote result (i.e., the message authentication code output by each AND operation unit). If yes, the to-be-verified masked vote result is taken as the masked vote result output by the AND operation unit. If no, the tallying party corresponding to the to-be-verified masked vote result that fails the verification is determined, and a message indicating that the verification fails is sent to the determined tallying party.
[0126]
[0127] wherein, represents the unit ciphertext corresponding to the AND operation unit sent by the tallying party Di to the tallying party, t = z' α , z' α represents the masked vote result input into the AND operation unit, s = z' β , z' β represents the masked vote result input into the AND operation unit, represents the label value input into the AND operation unit, This indicates the label value of the input AND operation unit. This indicates the voting result of the mask to be verified output by the AND operation unit. Indicates the voting results of the mask to be verified. The corresponding message verification code, which is the message verification code output by the AND operation unit, This represents the intermediate tag value output by the AND operation unit. This represents the message verification code indicating the unverified voting results of other voters Dj as determined by voter Di. This message verification code is determined by the vote counter based on the determined tag value and the ciphertext of this unit. This represents the key stored by voting party Di, which is the message verification code of the voting result to be verified by the output of the operation unit, determined by other voting parties Dj. Δ represents the voting result of the mask to be verified, determined by other voters Dj and output by the AND operation unit. i This represents the global key of voting party Di. This represents the tag value output by the AND operation unit. H(x) represents the hash function, γ represents the output of the AND operation unit, and s and t represent the two inputs of the AND operation unit, respectively.
[0128] In this specification, other voters can determine the initial tag value of the masked voting result based on the masked voting result published by the voters, and send it to the vote counting center. This initial tag value is a K-bit bit string randomly generated by other voters based on the masked voting result. Therefore, each masked voting result published by each voter corresponds to multiple initial tag values generated by the voters. Thus, in step S100 above, the vote counting center can receive the initial tag values corresponding to each masked voting result sent by each voter.
[0129] Based on this, in step S102 above, the vote counter can statistically analyze each mask voting result based on the pre-constructed vote counting tree, according to the voting results of each mask and the initial label values corresponding to each mask voting result, to determine the mask statistical results output by the vote counting tree. The specific process is similar to the process described above where each mask voting result corresponds to an initial label value, except that each mask voting result corresponds to multiple initial label values, and the label value output by each XOR operation unit and each AND operation unit contains a set of multiple label values. The specific process will not be elaborated here.
[0130] In the present specification, when the first results and the label commitment value are published, the tallying party can send the first results and the label commitment value to the bulletin board so that the first results and the label commitment value are known to the voting parties and the third party. Of course, when other content is published, such as the verification code aggregate commitment value, the content to be published can also be sent to the bulletin board, and the present specification does not make specific limitations.
[0131] The present specification also provides a method for electronic voting, which is applied to a voting party, and specifically includes the following steps: Figure 3 As shown in the flowchart of another method for electronic voting provided in the present specification, Figure 3 As shown in the flowchart of another method for electronic voting provided in the present specification, Figure 3 As shown in the flowchart of another method for electronic voting provided in the present specification,
[0132] S200: According to the voting options, determine the voting results, and according to the topology structure of the tallying tree constructed by the tallying party in advance, generate a mask bit share by using a secure multi-party computation preprocessing function.
[0133] S202: Process the voting results according to the mask bit share, determine the mask voting results, publish, and generate the initial label value corresponding to the mask voting results, and send the initial label value to the tallying party, so that the tallying party, based on the mask voting results published by the voting parties and the received initial label value, performs statistics on the mask voting results based on the tallying tree, determines the mask statistical results output by the tallying tree, and determines the first results and the intermediate label values output by each operation node in the tallying tree, and determines the label commitment value according to each intermediate label value, and publishes each first result and the label commitment value.
[0134] In order to protect the privacy contained in the voting results, the voting party can first determine the voting results according to the voting options, and then generate a mask bit share by using a secure multi-party computation preprocessing function according to the topology structure of the tallying tree constructed by the tallying party in advance. Then, according to the mask bit share, the voting results are processed to determine the mask voting results, which are published, and the initial label value corresponding to the mask voting results is generated and sent to the tallying party. The tallying tree is constructed by the tallying party according to the number of voting parties. The voting results are determined by the voting party according to the voting options. Different voting scenarios, different voting options, different voting results, and of course different voting parties. The specific voting parties and voting results in different voting scenarios are described above in step S100, and will not be described here. The secure multi-party computation preprocessing function is a function in the existing secure multi-party computation library. The initial label value corresponding to the mask voting results generated by the voting party can be a label value randomly generated based on the mask voting results.
[0135] Specifically, the voter can determine the voting result according to the voting option, generate a mask bit share by using a secure multi-party computation preprocessing function according to the topology of the counting tree published by the vote counter, process the voting result according to the mask bit share, determine a mask voting result, and generate an initial label value corresponding to the mask voting result. The mask voting result is published, and the initial label value is sent to the vote counter. The vote counter determines the mask statistical result output by the counting tree, the first result output by each operation node in the counting tree, and the intermediate label value according to the mask voting result published by each voter and the received initial label value, determines the label commitment value according to the intermediate label value, and publishes each first result and the label commitment value.
[0136] In this specification, each operation node can include an AND operation unit, and one operation node can include one or more AND operation units. Therefore, when each operation node includes several AND operation units, in addition to sending the initial label value corresponding to the mask voting result to the vote counter, the voter also needs to send the unit ciphertext corresponding to the AND operation unit in the counting tree to the vote counter. Therefore, the voter can determine the verifiable mask bit share input into each AND operation unit and the label value for each AND operation unit in each operation node in the counting tree in sequence, determine the triple of the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit by using a secure multi-party computation preprocessing function. Then, the unit ciphertext corresponding to the AND operation unit is determined according to the triple, the verifiable mask bit share input into the AND operation unit, the label value input into the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit. Then, the unit ciphertext corresponding to each AND operation unit in the counting tree and the initial label value corresponding to the mask voting result are sent to the vote counter.
[0137] If the operation node is an upstream operation node of a leaf node in the counting tree, the verifiable mask bit share input into the operation node is generated by the voter by using a secure multi-party computation preprocessing function, and the label value input into the operation node is a K-bit bit string randomly generated by the voter or the result of the exclusive OR operation between the K-bit bit string randomly generated by the voter and the global key, that is, the initial label value. If the operation node is not an upstream operation node of a leaf node in the counting tree, the verifiable mask bit share input into the operation node and the label value are the verifiable mask bit share and the label value output by the previous operation node of the operation node.
[0138] If the AND operation unit is the first operation unit in the operation node, the verifiable mask bit share and the tag value input into the AND operation unit are the verifiable mask bit share and the tag value input into the operation node. If the AND operation unit is not the first operation unit in the operation node, the verifiable mask bit share and the tag value input into the AND operation unit are the verifiable mask bit share and the tag value output by the previous operation unit of the AND operation unit.
[0139] In addition, when the previous operation unit of the AND operation unit is an AND operation unit, the verifiable mask bit share output by the previous operation unit of the AND operation unit is determined by using a secure multi-party computation preprocessing function, and is taken as the verifiable mask bit share input into the AND operation unit. Of course, in the present specification, the operation node can also include a plurality of XOR operation units, so when the previous operation unit of the AND operation unit can also be an XOR operation unit, the verifiable mask bit share and the tag value output by the previous operation unit (i.e. the XOR operation unit) of the AND operation unit are determined, the determined verifiable mask bit share is subjected to XOR operation, and the result of the operation is taken as the verifiable mask bit share output by the XOR operation unit. The determined tag value is subjected to XOR operation, and the result of the operation is taken as the tag value output by the XOR operation unit. The verifiable mask bit share and the tag value output by the XOR operation unit are taken as the verifiable mask bit share and the tag value input into the AND operation unit.
[0140] In the determination of the unit ciphertext corresponding to the AND operation unit according to the triple, the verifiable mask bit share input into the AND operation unit, the tag value input into the AND operation unit, the verifiable mask bit share output by the AND operation unit and the tag value output by the AND operation unit, the first value can be determined according to the first value in the triple and the first verifiable mask bit share input into the AND operation unit, and the second value can be determined according to the second value in the triple and the second verifiable mask bit share input into the AND operation unit. Specifically, the following formula can be used for calculation:
[0141]
[0142]
[0143] wherein the triple is three parameters generated by using a secure multi-party computation preprocessing function, and the triple includes the first value, the second value and the third value, i.e. the first value, the second value and the third value of the AND operation unit determined by the voter Di are and The verifiable mask bit share input into the AND operation unit includes a first verifiable mask bit share and a second verifiable mask bit share, that is, the first verifiable mask bit share and the second verifiable mask bit share determined by the voting party Di input into the AND operation unit are respectively and When the AND operation unit is the first operation unit of the operation node, and the operation node is an upstream operation node of a leaf node in the tally tree, and Both can be generated by the voting party based on a secure multi-party computation function, or can be 0, which is not specifically limited in the specification. represents the first value determined by the voting party Di, represents the second value determined by the voting party Di.
[0144] The above and When it is not 0, it can be represented by the following formula:
[0145]
[0146] wherein, represents the verifiable mask bit share input into the operation node or the AND operation unit generated by the voting party Di, represents the mask bit share generated by the voting party Di, represents the corresponding message authentication code, represents the key corresponding to the message authentication code of the mask bit share input into the operation node or the AND operation unit generated by the other voting party Dj.
[0147] Then, the first value and the second value are sent to other voting parties. The other voting parties are voting parties that belong to the operation node together with the voting party, that is, the other voting parties are voting parties other than the voting party (i.e., the above-mentioned voting party Di, which is the voting party as the execution subject) among the voting parties inputting data into the operation node. The third value and the fourth value sent by the other voting parties are received, the received third value and the first value are aggregated to determine the first total value, and the received fourth value and the second value are aggregated to determine the second total value, which can be calculated by the following formula:
[0148]
[0149]
[0150] wherein d γ represents the first total value determined by the voting party Di, and n represents the number of voting parties, represents the first value determined by the voting party Di, represents the third value determined by the voting party Dn, and sends the third value to the voting party Di, and the determination process of the first value and the third value is similar, which is determined locally by different voting parties. γ represents the second total value determined by the voting party Di, represents the second value determined by the voting party Di. represents the fourth value determined by the voting party Dn, and sends the third value to the voting party Di, and the determination process of the second value and the fourth value is similar, which is determined locally by different voting parties.
[0151] Then, according to the first total value, the second total value, the triple, the verifiable mask bit share output by the AND operation unit and the verifiable mask bit share input into the AND operation unit, the to-be-verified mask voting result output by the AND operation unit is determined, which can be calculated by the following formula:
[0152]
[0153]
[0154] wherein, represents the to-be-verified mask voting result output by the AND operation unit determined by the voting party Di, represents the verifiable mask bit share output by the AND operation unit determined by the voting party Di, which is generated by the voting party Di using a secure multi-party computing preprocessing function, t and s are bit values, and each t and s ∈ {0, 1}.
[0155] Then, according to the to-be-verified mask voting result output by the AND operation unit, the label value input into the AND operation unit and the label value output by the AND operation unit, the unit ciphertext corresponding to the AND operation unit is determined, which can be calculated by the following formula:
[0156]
[0157] wherein, represents the unit ciphertext corresponding to the AND operation unit determined by the voting party Di, since t can be 0 or 1, and s can be 0 or 1, t and s have 4 combination modes in total, each combination mode corresponds to a unit ciphertext, and therefore the unit ciphertext corresponding to the AND operation unit has 4, := is an assignment symbol, represents the label value input into the AND operation unit when the bit value determined by the voting party Di is t, represents the label value input into the AND operation unit when the bit value determined by the voting party Di is t, and γ represents the output of the AND operation unit, a message authentication code representing the to-be-verified masked vote result output by the AND operation unit, a label value output by the AND operation unit when the bit value determined by the vote party Di is 0, Δ i a global key of the vote party Di, a key corresponding to the message authentication code representing the to-be-verified masked vote result output by the AND operation unit determined by the other vote party Dj stored by the vote party Di.
[0158] If the AND operation unit is the first operation unit in the first operation node, and the first operation node is an upstream operation node of a leaf node in the tally tree, the above and are K-bit bit strings randomly generated by the vote party Di, and the bit values are t and s respectively.
[0159] In the present specification, since the masked vote result of a vote party is published to all other vote parties (i.e. other vote parties except the vote party), the other vote parties can determine the initial label value corresponding to the masked vote result according to the masked vote result published by the vote party, and send to the tally party. The initial label value is a K-bit bit string randomly generated by the other vote party based on the bit value of the masked vote result, and the specific process is similar to the process of generating the initial label value in step S202, which will not be described here. Based on this, the tally party can receive each initial label value corresponding to each masked vote result sent by each vote party.
[0160] S204: Determine each first result and label commitment value published by the tally party.
[0161] S206: Determine the label value output by each operation node in the tally tree according to each first result, and determine the verification commitment value of each label value according to the homomorphic commitment function, and publish the verification commitment value.
[0162] S208: Publicly verify the mask statistics result according to the label commitment value and the verification commitment value.
[0163] The voting party determines the first results and the label commitment value published by the tallying party, determines the label values output by each operation node in the tallying tree according to the first results, determines the verification commitment value of each label value according to the homomorphic commitment function, and publishes the verification commitment value. Then, the mask statistical result is publicly verified according to the label commitment value and the verification commitment value. The tallying tree includes a plurality of operation nodes. When the label values output by each operation node in the tallying tree are determined according to the first results, since the first results are the mask voting results output by each operation node in the tallying tree, the voting party can determine the mask voting results published by other voting parties. According to the mask voting results determined in the step S202, the mask voting results of other voting parties, and the first results, the mask statistical result output by the tallying tree is calculated according to each operation node in the tallying tree, and the label values output by each operation node in the tallying tree are determined.
[0164] When the verification commitment value of each label value is determined according to the homomorphic commitment function, the voting party can first aggregate the label values, and then determine the verification commitment value of the aggregated label values based on the homomorphic commitment function. The voting party can also first determine the commitment value corresponding to each label value based on the homomorphic commitment function, and take the result of aggregating the commitment values as the mask commitment value. The present specification does not make specific limitations.
[0165] In the present specification, the operation node can also include at least one of the XOR operation unit and the AND operation unit. Therefore, the label values corresponding to the verification commitment values are the label values output by each operation unit. In addition, since the mask voting result output by the XOR operation unit can be obtained by performing XOR operation on the mask voting results input into the XOR operation unit, and the mask voting results of each voting party are published, that is, anyone can know the mask voting results of each voting party, when the mask statistical result is publicly verified, the tallying party can only take the mask voting results output by each AND operation unit as the first results, determine the label commitment value corresponding to the label values output by each AND operation unit, and publish each first result and the label commitment value. Correspondingly, the voting party can also only determine the verification commitment value corresponding to the label values output by each AND operation unit, and publish it. The verification commitment value can be specifically represented as wherein, represents the label value output by the AND operation unit w determined by the voting party Di, and W represents the set of AND operation units.
[0166] In the step S208, the voting party can determine the verification commitment values published by other voting parties as other verification commitment values, aggregate the other verification commitment values and the verification commitment value, and then verify the mask statistical result according to the aggregated commitment value and the label commitment value. The aggregated commitment value can be represented as: wherein, n represents the number of voting parties.
[0167] The above verification of the mask statistic result according to the aggregated commitment value and the label commitment value is passed when the aggregated commitment value and the label commitment value are consistent. That is The verification of the mask statistic result is passed when the above formula is established. When the aggregated commitment value and the label commitment value are inconsistent or the above formula is not established, the verification of the mask statistic result is failed, and the vote side publishes a message that the verification of the mask statistic result is failed. Wherein, represents the label commitment value published by the vote side.
[0168] In addition, in addition to determining whether the mask statistic result is accurate by verifying whether the label value is accurate, the mask statistic result can be further determined to be accurate by verifying the mask vote result output by the operation node or the operation unit. Therefore, when the aggregated commitment value and the label commitment value are consistent in the above verification of the mask statistic result according to the aggregated commitment value and the label commitment value, the mask vote result published by the other vote side is determined. Then, for each and operation unit, the mask vote result input into the and operation unit is determined according to each mask vote result and each first result, and the verifiable mask bit share input into the and operation unit and the verifiable mask bit share output by the and operation unit are determined. Then, the verifiable check bit of the and operation unit is determined according to the determined verifiable mask bit share and the mask vote result. Then, the message authentication code of the and operation unit is determined according to the verifiable check bit, and the authentication code commitment value of the message authentication code is determined based on the homomorphic commitment function. Then, the sum of each authentication code commitment value is determined as a verification aggregated commitment value, and the verification aggregated commitment value is published. Then, the authentication code aggregated commitment value published by the vote side is determined, and the mask statistic result is publicly verified according to the authentication code aggregated commitment value and the verification aggregated commitment value. Wherein, the verifiable check bit of the and operation unit is determined according to the determined verifiable mask bit share and the mask vote result, which can be calculated by the following formula:
[0169]
[0170] Wherein, represents the verifiable check bit of the and operation unit determined by the vote side Di, z′ α and z′ β represents two mask vote results input into the and operation unit determined by the vote side Di, and represents two verifiable mask bit shares input into the and operation unit determined by the vote side Di, represents the verifiable mask bit share output by the and operation unit determined by the vote side Di.
[0171] Since the verifiable check bit is obtained by the above calculation, the verifiable check bit includes the message authentication code corresponding to the check bit, and the voter can directly determine the message authentication code of the AND operation unit from the verifiable check bit corresponding to the AND operation unit, that is, the message authentication code corresponding to the check bit. Based on the homomorphic commitment function, the authentication code commitment value of the message authentication code is determined, and the sum of each authentication code commitment value is determined as the verification aggregate commitment value, which can be expressed as wherein, represents the message authentication code of the AND operation unit w determined by the voter Di.
[0172] When the verification aggregate commitment value is determined based on the authentication code aggregate commitment value and the verification aggregate commitment value, the voter can determine the verification aggregate commitment value published by other voters, aggregate the verification aggregate commitment value of other voters and the determined verification aggregate commitment value, and perform public verification on the mask statistical result based on the aggregated verification commitment value and the authentication code aggregate commitment value. Wherein, the aggregated verification commitment value can be expressed as When the aggregated verification commitment value and the authentication code aggregate commitment value are consistent, it means that the mask statistical result passes the verification, that is, When the aggregated verification commitment value and the authentication code aggregate commitment value are consistent, it means that the mask statistical result passes the verification, that is,
[0173] S210: When the mask statistical result passes the verification, determine the mask bit share corresponding to the mask statistical result and publish it, so that the vote counter decrypts the mask statistical result based on the mask bit share published by each voter, determines the final voting result, and publishes the final voting result.
[0174] When the mask statistical result passes the verification, the voter determines the mask bit share corresponding to the mask statistical result and publishes it, so that the vote counter decrypts the mask statistical result based on the mask bit share published by each voter, determines the final voting result, and publishes the final voting result.
[0175] In order to ensure the accuracy of the mask bit shares published by the voting parties, when the mask statistical result is verified, the voting party can determine the mask bit share corresponding to the mask statistical result, determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish it, so that the tallying party verifies the mask bit share based on the mask commitment value corresponding to the mask bit share published by each voting party, and when each mask bit share is verified, the tallying party decrypts the mask statistical result based on each mask bit share, determines the final voting result, and publishes it. Wherein, the mask commitment value is used to verify whether the mask bit share is accurate, and the mask commitment value includes the original commitment value and other commitment values, so when the mask commitment value corresponding to the mask bit share is determined based on the homomorphic commitment function and published, the voting party can determine that the commitment value corresponding to the mask bit share is the original commitment value based on the homomorphic commitment function, determine the mask bit share corresponding to the mask statistical result published by other voting parties, and determine the other commitment values based on the mask bit share published by other voting parties based on the homomorphic commitment function, and publish the mask bit share, the original commitment value and the other commitment values. So that the tallying party determines that the sum of each original commitment value is a first value based on the original commitment value and the other commitment value published by each voting party, and determines that the sum of each other commitment value is a second value. When the first value is consistent with the second value, it is determined that each mask bit share is verified.
[0176] In this specification, when the voting party publishes the mask voting result, the mask voting result can be sent to the bulletin board so that other voting parties, tallying parties and third parties can know the mask voting result. Of course, when the voting party publishes other content, such as verifying commitment values, verifying aggregated commitment values and mask commitment values, etc., the content to be published can also be sent to the bulletin board, and this specification does not make specific limitations.
[0177] The above is the method of one or more embodiments of the present specification, based on the same idea, the present specification also provides a corresponding electronic voting device, which is applied to the tallying party, as shown in Figure 4
[0178] Figure 4 The structure diagram of an electronic voting device provided by the present specification comprises:
[0179] The first determination module 300 is used to determine the mask voting result published by each voting party, and receive the label value corresponding to the mask voting result sent by each voting party, wherein the mask voting result is the result of the voting party processing the voting result based on the mask bit share, and the mask bit share is generated by the voting party based on the secure multi-party computation preprocessing function;
[0180] The vote counting module 302 is configured to count the mask voting results based on the pre-constructed vote counting tree, determine a mask counting result output by the vote counting tree, and determine a first result output by each operation node and an intermediate label value according to the mask voting results and the initial label values; the vote counting tree comprises a plurality of operation nodes;
[0181] The publication module 304 is configured to generate a label commitment value of each intermediate label value based on the homomorphic commitment function, and publish the first results and the label commitment value, so that the voters verify the mask counting result publicly according to the first results and the label commitment value published by the vote counter;
[0182] The second determination module 306 is configured to determine mask bit shares corresponding to the mask counting result published by the voters when the mask counting result is verified.
[0183] The decryption module 308 is configured to decrypt the mask counting result according to the mask bit shares, determine a final voting result, and publish the final voting result.
[0184] Optionally, the operation node comprises a plurality of AND operation units.
[0185] The publication module 304 is specifically configured to determine a mask voting result input into each AND operation unit, and determine a verifiable mask bit share input into the AND operation unit and a verifiable mask bit share output by the AND operation unit based on a secure multi-party computation preprocessing function; determine a verifiable check bit of the AND operation unit according to the determined verifiable mask bit shares and the mask voting result; determine a message authentication code of the AND operation unit according to the verifiable check bit, and determine a commitment value of the message authentication code based on the homomorphic commitment function; determine a sum of the commitment values as an aggregated commitment value of the message authentication codes, and publish the aggregated commitment value of the message authentication codes, the first results and the label commitment value.
[0186] Optionally, the decryption module 308 is specifically configured to determine a mask commitment value corresponding to the mask bit share published by the voters; perform public verification on the mask bit shares according to the mask commitment values; and when the mask bit shares are verified, decrypt the mask counting result according to the mask bit shares to determine a final voting result.
[0187] Optionally, the mask commitment value comprises an original commitment value and other commitment values.
[0188] The decryption module 308 is specifically configured to determine, for each voter, an original commitment value corresponding to the mask bit share published by the voter and other commitment values, wherein the original commitment value is a commitment value determined by the voter based on the mask bit share corresponding to the voter, and the other commitment values are commitment values determined by the voter based on the mask bit shares published by other voters; determine a sum of the original commitment values as a first value, and a sum of the other commitment values as a second value; and determine that the mask bit shares are verified when the first value is consistent with the second value.
[0189] The present specification also provides an electronic voting device, which is applied to a voter, as shown in Figure 5
[0190] Figure 5 Another electronic voting device provided by the present specification has a structural schematic diagram, which includes:
[0191] The generation module 400 is configured to determine a voting result according to voting options, and generate mask bit shares by using a secure multi-party computing preprocessing function according to a topology structure of a vote counting tree constructed in advance by a vote counter;
[0192] The sending module 402 is configured to process the voting result according to the mask bit shares, determine a mask voting result, and publish the mask voting result, and generate an initial label value corresponding to the mask voting result, and send the initial label value to the vote counter, so that the vote counter counts the mask voting results according to the mask voting results published by the voters and the initial label value received, determines a mask counting result output by the vote counting tree based on the vote counting tree, determines first results output by each operation node in the vote counting tree and intermediate label values, determines label commitment values according to the intermediate label values, and publishes each first result and the label commitment values;
[0193] The determination module 404 is configured to determine each first result and the label commitment values published by the vote counter;
[0194] The commitment module 406 is configured to determine label values output by each operation unit in the vote counting tree according to the first results, determine verification commitment values of the label values according to a homomorphic commitment function, and publish the verification commitment values;
[0195] The verification module 408 is configured to publicly verify the mask counting result according to the label commitment values and the verification commitment values;
[0196] The mask module 410 is configured to determine the mask bit share corresponding to the mask statistic result when the mask statistic result passes the verification, and publish the mask bit share, so that the vote counter decrypts the mask statistic result according to the mask bit share published by each vote party, determines a final vote result, and publishes the final vote result.
[0197] Optionally, the verification module 408 is specifically configured to determine the verification commitment value published by the other vote party as an other verification commitment value; aggregate the other verification commitment value and the verification commitment value; and perform public verification on the mask statistic result according to the aggregated commitment value and the label commitment value.
[0198] Optionally, the operation node includes a plurality of AND operation units.
[0199] The verification module 408 is specifically configured to determine the mask vote result published by the other vote party when the aggregated commitment value is consistent with the label commitment value; determine, for each AND operation unit, the mask vote result input into the AND operation unit and the verifiable mask bit share input into the AND operation unit and the verifiable mask bit share output by the AND operation unit according to the mask vote result and the first result; determine the verifiable verification bit of the AND operation unit according to the determined verifiable mask bit share and the mask vote result; determine the message authentication code of the AND operation unit according to the verifiable verification bit, and determine the verification commitment value of the message authentication code based on the homomorphic commitment function; determine the sum of the verification commitment values as a verification aggregated commitment value, and publish the verification aggregated commitment value; determine the verification aggregated commitment value published by the vote counter, and perform public verification on the mask statistic result according to the verification aggregated commitment value and the verification aggregated commitment value.
[0200] Optionally, the mask module 410 is specifically configured to determine the mask bit share corresponding to the mask statistic result; determine the mask commitment value corresponding to the mask bit share based on the homomorphic commitment function, and publish the mask commitment value, so that the vote counter performs public verification on the mask bit share according to the mask commitment value corresponding to the mask bit share published by each vote party.
[0201] Optionally, the mask commitment value includes an original commitment value and an other commitment value.
[0202] The masking module 410 is specifically used to: determine the commitment value corresponding to the mask bit share as the original commitment value based on the homomorphic commitment function; determine the mask bit share corresponding to the mask statistics results published by other voters; and, based on the mask bit shares published by other voters and the homomorphic commitment function, determine other commitment values, and publish the mask bit share, the original commitment value, and the other commitment values.
[0203] This specification also provides a computer-readable storage medium storing a computer program that can be used to execute the above-described... Figure 1 This provides a method for electronic voting.
[0204] This instruction manual also provides Figure 6 One of the corresponding Figure 1 A schematic diagram of the structure of an electronic device. (e.g.) Figure 6 As shown, at the hardware level, this electronic device includes a processor, internal bus, network interface, memory, and non-volatile memory, and may also include other hardware required for business operations. The processor reads the corresponding computer program from the non-volatile memory into memory and then runs it to achieve the above. Figure 1 The aforementioned electronic voting method.
[0205] Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of hardware and software. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0206] In the 1990s, it was quite obvious to distinguish whether an improvement in a technology was in hardware (e.g., improvement in circuit structures of diodes, transistors, switches, etc.) or in software (improvement in method flow). However, as technology has evolved, many improvements in method flow today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flow into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented by hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming it, rather than by asking a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented by "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.
[0207] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to being implemented in pure computer readable program code, the controller can equally well be implemented to perform the same functions using logic gates, switches, an application specific integrated circuit, a programmable logic controller and an embedded microcontroller, etc. by means of a logical programming of the method steps. The controller can thus be considered as a hardware component, and the means comprised therein for performing the various functions can be considered as structures within the hardware component. Alternatively, the means for performing the various functions can even be considered as both a software module implementing the method and a structure within the hardware component.
[0208] The systems, apparatuses, modules or units illustrated by the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0209] For the sake of description, the above apparatuses are described in various units with functions respectively. Of course, the functions of the units can be implemented in one or more software and / or hardware in implementing the present specification.
[0210] Those skilled in the art will understand that the embodiments of the present specification can be provided as a method, a system or a computer program product. Therefore, the present specification can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0211] The specification is presented with reference to flow diagrams and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the specification. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing element or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Although the flow diagrams and / or block diagrams can present a method, apparatus or computer program product in a particular, it is understood that the method, apparatus and computer program product can include one or more additional steps, operations, or functions, and the method, apparatus and computer program product can include fewer than all of the steps, operations, or functions shown in the figures. Additionally, the steps, operations, or functions need not be implemented in the order shown in the figures. Further, the steps, operations, or functions can be implemented in parallel, or can be performed by parallel processors or computers. Figure 1 These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks.
[0212] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Although the flow diagrams and / or block diagrams can present a method, apparatus or computer program product in a particular, it is understood that the method, apparatus and computer program product can include one or more additional steps, operations, or functions, and the method, apparatus and computer program product can include fewer than all of the steps, operations, or functions shown in the figures. Additionally, the steps, operations, or functions need not be implemented in the order shown in the figures. Further, the steps, operations, or functions can be implemented in parallel, or can be performed by parallel processors or computers. Figure 1 These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks.
[0213] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Although the flow diagrams and / or block diagrams can present a method, apparatus or computer program product in a particular, it is understood that the method, apparatus and computer program product can include one or more additional steps, operations, or functions, and the method, apparatus and computer program product can include fewer than all of the steps, operations, or functions shown in the figures. Additionally, the steps, operations, or functions need not be implemented in the order shown in the figures. Further, the steps, operations, or functions can be implemented in parallel, or can be performed by parallel processors or computers. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks.
[0214] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0215] The memory can include non-persistent memory, random access memory (RAM), and / or non-volatile memory, etc. in the form of computer-readable media, such as read only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0216] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0217] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0218] Those skilled in the art will appreciate that embodiments of the present specification can be provided as methods, systems or computer program products. Therefore, the present specification can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0219] The present specification can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The present specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.
[0220] The various embodiments described in this specification are described using a numbering of embodiments approach: these are each individually integrated contributions pertaining to different aspects of the description. For each embodiment, the description focuses on the differences from the other embodiments. Each embodiment is to be read in isolation, with the understanding that the same or similar features from other embodiments can be combined with the features of the respective embodiment. In particular, the description of the system embodiments is kept relatively short, as the system embodiments are largely analogous to the method embodiments.
[0221] The above only describes the embodiments of the present specification and is not intended to limit the present specification. The present specification can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present specification shall be included in the scope of claims of the present specification.
Claims
1. A method of electronic voting, characterized in that, The method is applied to a vote counting party, and the method comprises: determining a mask vote result published by each vote party and receiving an initial tag value corresponding to the mask vote result sent by the vote party, wherein the mask vote result is a result of processing a vote result by the vote party according to a mask bit share, and the mask bit share is generated by the vote party based on a secure multi-party computation preprocessing function; based on each mask vote result and each initial tag value, counting the mask vote results based on a vote counting tree constructed in advance, determining a mask counting result output by the vote counting tree, and determining a first result output by each operation node and an intermediate tag value; wherein the vote counting tree comprises a plurality of operation nodes; based on a homomorphic commitment function, generating a tag commitment value of each intermediate tag value, and publishing each first result and the tag commitment value, so that each vote party publicly verifies the mask counting result according to the first result and the tag commitment value published by the vote counting party; when the mask counting result is verified, determining a mask bit share corresponding to the mask counting result published by each vote party; decrypting the mask counting result according to the mask bit share, determining a final vote result, and publishing the final vote result.
2. The method of claim 1, wherein, The operation node comprises a plurality of AND operation units; publishing each first result and the tag commitment value, specifically comprising: for each AND operation unit, determining a mask vote result input into the AND operation unit, and based on a secure multi-party computation preprocessing function, determining a verifiable mask bit share input into the AND operation unit and a verifiable mask bit share output by the AND operation unit; determining a verifiable test bit of the AND operation unit according to the determined verifiable mask bit share and the mask vote result; determining a message authentication code of the AND operation unit according to the verifiable test bit, and determining a verification code commitment value of the message authentication code based on the homomorphic commitment function; determining the sum of each verification code commitment value as a verification code aggregation commitment value, and publishing the verification code aggregation commitment value, each first result and the tag commitment value.
3. The method of claim 1, wherein, Decrypting the mask counting result according to the mask bit share to determine the final vote result, specifically comprising: determining a mask commitment value corresponding to the mask bit share published by each vote party; publicly verifying each mask bit share according to each mask commitment value; when the mask bit share is verified, decrypting the mask counting result according to the mask bit share to determine the final vote result.
4. The method of claim 3, wherein, The mask commitment value comprises an original commitment value and other commitment values; determining the mask commitment value corresponding to the mask bit share published by each vote party, specifically comprising: for each vote party, determining an original commitment value corresponding to the mask bit share published by the vote party and other commitment values, wherein the original commitment value is a commitment value determined by the vote party based on the mask bit share corresponding to the vote party, and the other commitment values are commitment values determined by the vote party based on the mask bit share published by other vote parties; According to each mask commitment value, the mask bit shares are publicly verified, specifically including: Determine the sum of each original commitment value as a first value, and determine the sum of each other commitment value as a second value; When the first value is consistent with the second value, it is determined that the mask bit shares are verified.
5. A method of electronic voting, characterized by The method is applied to a voting party, and the method includes: According to the voting options, determine the voting results, and according to the topology structure of the vote tree constructed by the vote party in advance, generate mask bit shares by using a secure multi-party computing preprocessing function; According to the mask bit shares, process the voting results to determine the mask voting results, and publish them, and generate the initial label value corresponding to the mask voting results, and send the initial label value to the vote party, so that the vote party counts each mask voting result based on the mask voting results published by each voting party and the received initial label value, determines the mask statistical result output by the vote tree, and determines the first result output by each operation node in the vote tree and the intermediate label value, and determines the label commitment value according to each intermediate label value, and publishes each first result and the label commitment value; Determine each first result and the label commitment value published by the vote party; According to the first result, determine the label value output by each operation node in the vote tree, and determine the verification commitment value of each label value according to the homomorphic commitment function, and publish the verification commitment value; According to the label commitment value and the verification commitment value, the mask statistical result is publicly verified; When the mask statistical result is verified, the mask bit shares corresponding to the mask statistical result are determined and published, so that the vote party decrypts the mask statistical result according to the mask bit shares published by each voting party to determine the final voting result, and publishes the final voting result.
6. The method of claim 5, wherein, According to the label commitment value and the verification commitment value, the mask statistical result is publicly verified, specifically including: Determine the verification commitment value published by the other voting party as the other verification commitment value; Aggregate the other verification commitment value and the verification commitment value; According to the aggregated commitment value and the label commitment value, the mask statistical result is publicly verified.
7. The method of claim 6, wherein, The operation node includes a plurality of and operation units; According to the aggregated commitment value and the label commitment value, the mask statistical result is publicly verified, specifically including: When the aggregated commitment value is consistent with the label commitment value, it is determined that the mask voting result published by the other voting party is verified. For each and operation unit, according to each mask voting result and each first result, determine the mask voting result input into the and operation unit, and determine the verifiable mask bit share input into the and operation unit and the verifiable mask bit share output by the and operation unit; According to the determined verifiable mask bit share and the mask voting result, determine the verifiable test bit of the and operation unit; According to the verifiable check bits, a message authentication code of the operation unit is determined, and a verification commitment value of the message authentication code is determined based on the homomorphic commitment function; A sum of the verification commitment values is determined as a verification aggregate commitment value, and the verification aggregate commitment value is published; The verification aggregate commitment value is determined based on the verification aggregate commitment value and the verification aggregate commitment value, and the mask statistical result is publicly verified.
8. The method of claim 5, wherein, The mask bit share corresponding to the mask statistical result is determined and published, specifically including: The mask bit share corresponding to the mask statistical result is determined; Based on the homomorphic commitment function, a mask commitment value corresponding to the mask bit share is determined and published, so that the vote counting party publicly verifies the mask bit share based on the mask commitment value corresponding to the mask bit share published by each vote party.
9. The method of claim 8, wherein, The mask commitment value includes an original commitment value and other commitment values; Based on the homomorphic commitment function, a mask commitment value corresponding to the mask bit share is determined and published, specifically including: Based on the homomorphic commitment function, the commitment value corresponding to the mask bit share is determined as an original commitment value; The mask bit share corresponding to the mask statistical result published by the other vote party is determined, and based on the mask bit share published by the other vote party, other commitment values are determined based on the homomorphic commitment function, and the mask bit share, the original commitment value and the other commitment values are published.
10. An apparatus for electronic voting, characterized by The device is applied to a vote counting party, and the device includes: A first determination module is configured to determine mask voting results published by each vote party and receive initial label values corresponding to the mask voting results sent by the vote parties, wherein the mask voting result is a result obtained by processing a voting result based on a mask bit share by the vote party, and the mask bit share is generated by the vote party based on a secure multi-party computation preprocessing function; A vote counting module is configured to count the mask voting results based on a pre-constructed vote counting tree, determine a mask statistical result output by the vote counting tree, and determine first results and intermediate label values output by each operation node based on each mask voting result and each initial label value, wherein the vote counting tree includes a plurality of operation nodes; A publishing module is configured to generate label commitment values of each intermediate label value based on a homomorphic commitment function, and publish each first result and the label commitment values, so that each vote party publicly verifies the mask statistical result based on each first result and the label commitment values published by the vote counting party; A second determination module is configured to determine mask bit shares corresponding to the mask statistical result published by each vote party when the mask statistical result passes verification. A decryption module is configured to decrypt the mask statistical result based on each mask bit share, determine a final voting result, and publish the final voting result.
11. An apparatus for electronic voting, characterized by The device is applied to a vote party, and the device includes: The generating module is configured to determine a voting result according to the voting options, and generate a mask bit share by using a secure multi-party computation preprocessing function according to a topology structure of a vote counting tree pre-constructed by the vote counting party; The sending module is configured to process the voting result according to the mask bit share, determine a mask voting result, and publish the mask voting result, and generate a label value corresponding to the mask voting result, and send the label value to the vote counting party, so that the vote counting party counts the mask voting results of all the vote counting parties based on the vote counting tree according to the mask voting results published by all the vote counting parties and the received label value, determines a mask counting result output by the vote counting tree, and determines first results output by operation nodes in the vote counting tree and intermediate label values, determines a label commitment value according to the intermediate label values, and publishes the first results and the label commitment value; The determining module is configured to determine the first results and the label commitment value published by the vote counting party; The commitment module is configured to determine label values output by operation units in the vote counting tree according to the first results, determine verification commitment values of the label values according to a homomorphic commitment function, and publish the verification commitment values; The verification module is configured to publicly verify the mask counting result according to the label commitment value and the verification commitment values; The mask module is configured to determine mask bit shares corresponding to the mask counting result when the mask counting result passes the verification, and publish the mask bit shares, so that the vote counting party decrypts the mask counting result according to the mask bit shares published by all the vote counting parties, determines a final voting result, and publishes the final voting result.
12. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to implement the method in any one of claims 1-9.
13. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to implement the method in any one of claims 1-9.
Citation Information
Patent Citations
Verifiable, secret shuffles of encrypted data, such as elgamal encrypted data for secure multi-authority elections
CA2550259A1
Ethereum-based distributed anonymous voting method, apparatus and device, and medium
CN116452135A