A Verifiable General Electronic Voting Method Based on Private Set Intersection
By adopting a verifiable general electronic voting method based on privacy set requests in the electronic voting system, the problem of large economic expenses and inability to keep voting information confidential in the existing system is solved, effectively protecting voting information and verifiability of results are achieved, and it is suitable for diversified voting needs.
Patent Information
- Application Number
- CN202410642719.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-23
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-05-23
AI Technical Summary
The existing electronic voting system has problems such as excessive economic expenses and inability to effectively keep voting information confidential, and most solutions cannot support flexible voting models and cannot meet today's diverse voting needs.
A verifiable universal electronic voting method based on Privacy Set Interception (PSI) is adopted to achieve the privacy protection of voters and the verifiability of voting results through ElGamal encryption algorithm and symmetric encryption technology. The election agency aggregates the ballots, uses joint public key decryption to obtain the counting results, and generates zero-knowledge proofs to ensure the correctness of the results.
The electronic voting process is simplified, and the unrealistic model setting is eliminated, and the verification that voters vote correctly does not rely on non-interactive zero-knowledge proofs, achieving effective confidentiality of voting information and verifiability of results. This approach also has a wide range of potential applications, suitable for any aggregation scenario where privacy is required.
Smart Images

Figure CN118709199B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptography, and particularly to a verifiable general electronic voting method based on private set intersection. Background Art
[0002] Voting is the cornerstone of a democratic society and plays a crucial role in various democratic processes such as general elections, referendums, and parliaments. The proper conduct of elections ensures the correct implementation of democracy. However, traditional paper ballot voting, despite its long lifespan, has been subject to various doubts, such as inaccuracy, lack of transparency, a slow vote-counting process, and public distrust, especially when voters believe that the vote-counting clerks handling their ballots are dishonest, which is particularly evident among the youth. When the scale of elections gradually increases and election matters become increasingly complex and other real-world situations occur, these factors pose huge challenges to traditional paper voting. Therefore, in order to better complete democratic elections, electronic voting (E-voting) systems based on modern communication technology and cryptographic encryption technology have received a great deal of attention from scholars.
[0003] Electronic voting systems that employ hardware, software, and communication technologies have become a promising solution to address these issues, aiming to reduce human intervention and potential errors. Moreover, electronic voting schemes that utilize modern cryptographic technologies can protect the privacy of voters. Compared with traditional paper voting, electronic voting has prominent advantages. For example, when the COVID-19 pandemic gave rise to the need for remote voting solutions, implementing remote voting solutions would provide safeguards for the community. Additionally, countries such as Brazil and India have applied electronic voting to various national affairs, and countries such as the United States have also used electronic voting in the voting processes of various conferences and legislations.
[0004] Given concerns about privacy, verifiability, and scalability, the adoption of electronic voting has not been without doubts and debates. In today's increasingly complex social situation, the demand for voting among the public is growing stronger, leading to the emergence of diverse and complex voting rules. A single voting rule can no longer meet the needs of the public. However, most electronic voting schemes are designed for a specific voting rule. They use specific cryptographic tools to meet the requirements of rapid elections under specific conditions, but this also limits their ability to support flexible voting modes and fails to meet the current voting needs. At the same time, in order to ensure the secrecy and privacy protection of ballots in voting schemes without assuming a trusted authority, many voting schemes set up a large number of ballot counters to disperse the power of the election institution during the ballot counting stage. Then, through various cryptographic encryption tools, they are re-aggregated with the election institution to generate the ballot counting result. The advantage of this setting is to avoid the problem of privacy leakage caused by excessive power of the election institution. However, this setting method is actually not reasonable. First of all, a large number of ballot counters will result in a large amount of economic expenditure, which is a realistic factor that most schemes do not consider. Secondly, the setting of ballot counters increases the communication overhead of the protocol, which is not friendly to voters who need to vote online.
[0005] Based on the above, there is a practical need to design a general-purpose electronic voting scheme. Therefore, the present invention aims to provide a verifiable general electronic voting method based on private set intersection to improve some problems existing in the existing voting methods. Summary of the Invention
[0006] Aiming at the deficiencies of the prior art, the present invention provides a verifiable general electronic voting method based on private set intersection, which solves the problems of excessive economic expenditure and ineffective confidentiality of voting information in the existing voting methods.
[0007] To achieve the above objectives, the present invention is realized through the following technical solutions: A verifiable general electronic voting method based on private set intersection, including the following method steps:
[0008] S1. Initialization stage:
[0009] S101. Generate initialization parameters. The election institution will generate the necessary parameters for the election and publish them on the bulletin board, including the list of candidates to be elected, the list of eligible voters, and the security parameters;
[0010] S102. Each voter P i runs the ElGamal encryption algorithm to generate the corresponding private key El.Gen(λ) = sk i ∈Z q and calculates the public key according to the generated private key private key ski The corresponding public key is pk i , and each voter P i publishes his own identity identifier and public key (i, pk i ) on the bulletin board;
[0011] S103. The election authority aggregates the public keys of the voters on the bulletin board into a combined public key Finally, the public parameters are published on the bulletin board;
[0012] S2. Voting stage:
[0013] S201. The election authority generates its own ballot ba EA , and randomly shuffles the order;
[0014] S202. Voter P i generates his own ballot according to the candidate list C = {C 1 , C 2 , …, C m} published by the election authority on the bulletin board during the initialization stage, and assigns corresponding scores to the candidates;
[0015] S203. Voter P i runs the ElGamal encryption algorithm to encrypt the scores to obtain score ciphertexts, and generates corresponding symmetric encryption keys according to the candidate entries, runs symmetric encryption to encrypt the score ciphertexts to obtain double-encrypted ciphertexts, and associates the scores with the candidates at the ciphertext level;
[0016] S204. Sends the score ciphertexts and double-encrypted ciphertexts to the election authority, and at the same time shares the symmetric encryption keys with the election authority using the private set intersection technology based on the Diffie-Hellman key agreement protocol;
[0017] S3. Vote counting stage:
[0018] S301. After receiving the ciphertexts, the election authority runs the decryption algorithm of symmetric encryption to obtain the score ciphertexts;
[0019] S302. The election authority aggregates the score ciphertexts, then uses the combined public key to decrypt to obtain the vote counting result, generates the election result according to the voting rules, and generates a zero-knowledge proof of the election result;
[0020] S303. Publishes the election result and the corresponding zero-knowledge proof on the bulletin board;
[0021] S4. Public verification stage:
[0022] All participants verify the accuracy of the vote counting process. For the validity of the election results, external reviewers check the zero-knowledge proofs to confirm the results or re-aggregate the votes;
[0023] S5. Vote Format Verification:
[0024] The election authority verifies the legality of each vote. If a vote is found to be illegal, the vote counter can retrieve the vote and use the retrieved vote as evidence of voter dishonesty.
[0025] Preferably, in the step S101, the initialization parameters include the candidate list C = {C 1 , C 2 , …, C m}, the start and end times of the election, the list of eligible voters P = {P 1 , P 2 , …, P n}, the security parameter λ, the hash function H: {0, 1} * → Z q , the voting rules, and the CRS required for the election authority to generate Groth16 SNARK zero-knowledge proofs based on the security parameter λ s .
[0026] Preferably, in a verifiable general electronic voting method based on private set intersection, it is characterized in that in the step S203, for j ∈ [m], the score voted by the voter P i for the candidate C j is The voter needs to encrypt the score with the public key generated in step S1 to generate a ciphertext of the score. Subsequently, the voter P i uses the random number r i that has been pre-generated in the initialization phase and the candidate entry y j in his vote to generate a symmetric encryption key The voter then uses symmetric encryption to encrypt the previously encrypted score
[0027] Preferably, in the step S301, W j represents the aggregated ciphertext of the scores voted by each voter for the candidate C j .
[0028] Preferably, in step S4, the accuracy judgment expression of the zero-knowledge proof is: Verify(CRS VK , f res (v 1 , v 2 , …, vm ), π) → 0 / 1。
[0029] Preferably, in the step S5, for the PLURALITY voting rule, when the ballot score is legal, and the score during voting satisfies When the election authority or any external observer has doubts about the ballot submitted by the voter, the election authority calculates the product If the voter votes honestly, the product of the above formula is 0. To prevent all votes of the voter from being 0, the election authority needs to check the total score and ensure that the sum is 1.
[0030] Preferably, in the step S5, for the VETO rule, when the election authority or any external observer has doubts about the ballot submitted by the voter, the election authority needs to check the product of each item on the ballot whether it is equal to 0, and finally check the sum of the ballot scores,
[0031] Preferably, in the step S5, for the APPROVAL rule, the voter can only cast K ballots with a score of 1, and all the remaining candidates are voted 0. The election authority detects the sum of the scores of the voter's ballot and simultaneously checks the product S of the scores of the voter's ballot i ·(S i - 1)·(S i - 2)·…·(S i - K). When the product of the above formula is 0, the voter's ballot is legal, and any result other than 0 will prove that P i cheats.
[0032] Preferably, in the step S5, for the RANGE rule, the single score of the ballot the ballot is legal when, and the election authority detects the value of a polynomial product When and only when the polynomial product is 0, the election authority accepts the score of the ballot as correct.
[0033] Preferably, in the step S5, for the BORDA rule, the correct voting form needs to meet the following two conditions:
[0034]
[0035] For the detection of equation (1), use the method as above. For the verification of equation (2), calculate The election authority generates a random secret element in the domain Z q denoted as r j,l, j ≠ l ∈ [ m ] , then perform the multiplication operation, that is At r j,l In the case of ≠ 0, the product of the above formula If and only if Complete the verification of the correctness of the ballot format without revealing information about the information.
[0036] The present invention provides a verifiable general electronic voting method based on private set intersection. It has the following beneficial effects:
[0037] 1. The present invention simplifies the electronic voting process by utilizing the PSI property. The design of this scheme allows the calculation of votes and results in the case of only one semi-honest center participating, thus eliminating the unrealistic model settings required by the original electronic voting scheme.
[0038] 2. Through the method provided by the present invention, verifying whether a voter votes correctly does not depend on non-interactive zero-knowledge proofs. In addition to the aggregated vote with privacy protection function, the protocol provided by the present invention also has a wide range of potential applications. The electronic voting protocol can be used in any privacy-protected aggregation scenario, including the aggregation of commercial data, health data, critical infrastructure data, privacy-protected consensus building, model update of industrial control decisions, or federated learning. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is the system flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0041] Embodiment:
[0042] In the content of the present invention, this method has four entities: the election authority, the voter, the bulletin board, and the external observer.
[0043] Election Authority: The election authority is responsible for supervising the entire electronic voting process and plays a key role in the implementation process. They must announce important information on the bulletin board, including providing the eligible voters who can participate in the election and the list of candidates. Then collect the encrypted ballots from the voters and finally generate the election results, as well as the corresponding zero-knowledge proofs to ensure the verifiability of the election results.
[0044] Voters: Voters are an important part of the election process. They vote independently based on the candidate list and personal preferences. In the final stage of the election, voters must also verify the election results.
[0045] Bulletin Board: The information posted on the bulletin board is open to everyone and is mainly issued by the election authority. Voters generate their personal ballots based on the information on the bulletin board, and external observers use the zero-knowledge proofs provided on the bulletin board to confirm the accuracy of the election results.
[0046] External Observers: Used to monitor the proper conduct of the entire election process and verify the correctness of the final election results. In reality, this role is usually played by government officials or trustworthy individuals.
[0047] To reasonably achieve the collection of voters' ballots and generate correct election results, this method is divided into four stages, as shown in the appendix. Figure 1 As shown.
[0048] Initialization Stage: The election authority posts all pre-negotiated election parameters on the bulletin board. The election authority and all participating parties jointly generate public keys and corresponding private keys. Since the election authority must perform PSI to obtain the intersection set, it generates its own ballot, but cannot vote, that is, generates a non-scoring ballot containing all candidates.
[0049] Voting Stage: In the voting stage, voters create their personal ballots based on the information posted on the bulletin board. Voters vote for each candidate according to their personal preferences, and the scores must be non-negative and bounded values. Then, the voter encrypts the scores using the public key generated in the setup stage.
[0050] Counting Stage: Voters and the election authority perform multi-party PSI. The election authority aggregates the ballots to determine the scores of each candidate and the final counting result. The final election result is determined according to the selected voting method. The election authority must create corresponding zero-knowledge proofs for the election results to prove that they indeed originate from the counting result. The result and the SNARK proof are then posted on the bulletin board.
[0051] Public Verification Stage: All participants, including external observers and voters, are able to verify the accuracy of the counting process. Specifically, they can check the accuracy of all zero-knowledge proofs (ZKP).
[0052] The following will further introduce and explain the content of the present invention in combination with specific embodiments:
[0053] Please refer to the appendix. Figure 1, an embodiment of the present invention provides a verifiable general electronic voting method based on private set intersection. To facilitate the discussion of the method, some relevant parameters need to be predefined in advance. Assume that there are a total of m candidates C = {C 1 , C 2 , …, C m} for which an election needs to be conducted, and there are n voters P = {P 1 , P 2 , …, P n} participating in the election, where the subscript represents the unique identity identifier of the voter. The election authority and the voters have pre - negotiated the security parameter λ, as well as the group G ∈ G(λ), and all participating parties can access the random oracle RO;
[0054] Specifically, this verifiable general electronic voting method includes the following method steps:
[0055] S1. Initialization phase:
[0056] S101. In this phase, the election authority needs to generate all the initialization parameters for the election and announce them on the bulletin board, including the candidate list C = {C 1 , C 2 , …, C m}, the start and end times of the election, the list of eligible voters P = {P 1 , P 2 , …, P n}, as well as the security parameter λ jointly negotiated with the voters and external observers, the hash function H: {0, 1} * → Z q , and one of the five fractional voting rules, the voting method f res , etc. The election authority generates the CRS required for Groth16 SNARK zero - knowledge proof based on the security parameter λ s ;
[0057] Since the election authority needs to perform multi - party PSI with the voters, the election authority needs to generate its own ballot and initialize it as ba EA = (x 1 , x 2 , …, x m ), x i ∈ C. The election authority only generates ballots containing candidates but does not score each candidate. This is to ensure the authenticity of the election result. This step is for the election authority to generate an intersection with the voters during the subsequent multi - party PSI and finally obtain the vote - counting result;
[0058] S102. Each voter P i runs the ElGamal encryption algorithm to generate the corresponding private key El.Gen(λ) = sk i∈Z q , calculate the public key according to the generated private key Then the private key sk i The corresponding public key is pk i , each voter P i needs to publish his own identity identifier and public key (i, pk i ) on the bulletin board;
[0059] S103. The election authority aggregates the public keys of the voters on the bulletin board into a combined public key Then PK is the public key of all participants. Finally, the public parameters param = (C, P, λ, H, f res , CRS s , PK) are published on the bulletin board;
[0060] S2. Voting phase:
[0061] S201. In this phase, the voter needs to complete his vote and send the vote to the election authority through multi-party private set intersection. Then the election authority collects the votes to complete the voting phase. First, the election authority needs to randomly shuffle the order of its votes ba EA . Subsequently, each voter P i generates his own vote according to the candidate list C = {C 1 , C 2 , …, C m} published by the election authority on the bulletin board in the initialization phase, and assigns corresponding scores to the candidates he likes;
[0062] S202. The vote generated by voter P i is To ensure the correct format of the voter's vote, it is necessary to verify the correctness of the vote score, which will be discussed in detail later. Each voter P i also needs to randomly select a random number and keep it secret. Then the election authority randomly selects a random number a ∈ Z q ;
[0063] S203. To prevent the election authority from learning voter privacy based on the votes, we need a blinding process to further link the candidates while hiding information about the votes and candidates. The election authority first generates the key A j = {H(x j ) a |j ∈ [m]} and sends it to each voter. Voter P i calculates and returns it to the election authority. The election authority aggregates the received and obtains
[0064] For \(j\in[m]\), assume voter \(P\) i gives a score to candidate \(C\) j which is Then the voter needs to encrypt the score using the public key generated in the initialization phase to generate a ciphertext of the score. Subsequently, voter \(P\) i uses the random number \(r\) that has been pre-generated in the initialization phase i and the candidate entry \(y\) in his / her ballot j to generate a symmetric encryption key To link the score and the candidate at the ciphertext level and also for the blinding process for the pairing process of PSI, the voter will use the symmetric encryption to encrypt the previously generated ciphertext of the score
[0065] S3. Vote Counting Phase:
[0066] S301. In this phase, the election authority collects all the ballots of the voters and aggregates them to obtain for \(j\in[m]\), \(W\) j representing the aggregated ciphertext of the scores given by each voter to candidate \(C\) j . Since the election authority obtained the blinded matching items in the previous phase, the election authority needs to compare \(B\) j and to see if they are equal. For the matching items, the election authority can decrypt to obtain the aggregated ciphertext of the scores of the corresponding candidates:
[0067] \(V\) j = Sym.Dec(\(B\) j , \(E\) j ), for \(j\in[m]\)
[0068] S302. Then the election authority uses the joint public key to decrypt to obtain the final score of each candidate \(El.Dec(PK, V\) j ) = \(v\) j , generates the vote counting result of the final candidates \(((C\) 1 , \(v\) 1 ), (C\) 2 , \(v\) 2 ), …, (C\) m , \(v\) m ))), and finally generates the final election result \(f\) res \((v\) 1 , \(v\) 2 , …, \(v\) m ) according to the voting rules;
[0069] S303. Then the election authority needs to generate a non-interactive zero-knowledge proof Prove(CRS EK , f res (v 1 , v 2 , …, v m ), v j ) → π. The voter P i sends the ciphertext and to the election authority. Finally, the election authority publishes the election result f res (v 1 , v 2 , …, v m ) and the zero-knowledge proof π on the bulletin board;
[0070] S4. Public verification stage:
[0071] In the final stage, all participants can verify the accuracy of the vote counting process, especially the accuracy of the zero-knowledge proof (ZKP), Verify(CRS VK , f res (v 1 , v 2 , …, v m ), π) → 0 / 1. If there are any doubts about the validity of the election result, external reviewers can check the zero-knowledge proof to confirm the result, or, the votes can be re-aggregated to ensure the correctness of the election result;
[0072] S5. Ballot format verification:
[0073] To enable the election authority to verify the legality of each ballot, even if these ballots remain hidden from them, if a ballot is found to be illegal, the ballot counter can take back the ballot and use the retrieved ballot as evidence of voter dishonesty. Next, how to verify the ballot format specifications under each voting rule will be discussed in detail;
[0074] Specifically, among the voting rules used in the above steps, there are five rules including PLURALITY, VETO, APPROVAL, RANGE, and BORDA. Among them, the application of each rule is as follows:
[0075] PLURALITY rule:
[0076] In this voting rule, only when is the case, the ballot score is legal, and it can be clearly seen that when voters vote honestly, the score should satisfy When the election authority or any external observer has doubts about the ballot submitted by a voter, the election authority can calculate the product If the voters vote honestly, the product in the above formula must be 0. Through the above calculation, the election authority can verify whether the votes are compliant without knowing the specific distribution of the voters' ballots. To prevent the situation where all the voters' votes are 0, the election authority also needs to check the total score and meet the requirement that the sum is 1, that is
[0077] VETO rule:
[0078] Similar to the PLURALITY voting rule mentioned above, if the election authority or any external observer has doubts about the ballots submitted by the voters, the election authority needs to check the product of each item on the ballot whether it is equal to 0. Finally, check the sum of the ballot scores,
[0079] APPROVAL rule:
[0080] In the APPROVAL voting rule, it is required that the voter can vote at most K ballots with a score of 1, and all the remaining candidates can only vote 0. Therefore, the election authority can detect the sum of the scores of the voters' ballots And the election authority also needs to check the product S of the scores of the voters' ballots i ·(S i -1)·(S i -2)·…·(S i -K). Only when the product of the above formula is 0, will the election authority accept that the voter's ballot is legal. Because if the product is equal to 0, the election authority can infer that voter P i has voted for at most K candidates, without knowing the exact number of candidates that P i has voted for, nor knowing which candidates the voter has voted for. Therefore, any result other than 0 will prove that P i has cheated;
[0081] RANGE rule:
[0082] In the RANGE voting rule, what I need to understand is that only when the single score of the ballot is the ballot legal. Similar to the APPROVAL voting rule mentioned above, the election authority needs to detect the value of a polynomial product . Only when the product of this polynomial is 0, will the election authority accept that the scoring of this ballot is correct;
[0083] BORDA rule:
[0084] The ballot form for detecting the Borda voting rule may be slightly different from the above. According to this rule, the correct ballot form needs to meet the following two conditions:
[0085]
[0086] The detection of equation (1) can be carried out using the above method. For the verification of equation (2), the method can simply calculate However, for the privacy reasons of the ballots, the election authority shall not reveal these differences because they will disclose the entire ballot. To prevent such information leakage and still allow verification, the election authority can generate a random secret element in the domain Z q denoted as r j,l , j≠l∈[m], and then perform the product operation, that is When the finite field Z q is large enough, the probability that the selected random number is not 0 is very high (the probability is 1 / −p). Then in this case, when r j,l ≠0, the product of the above formula if and only if In this way, it is possible to verify the correctness of the ballot format without revealing any information about (because r j,l can be any non-zero element when the finite field is large enough).
[0087] Specifically, the present invention simplifies the electronic voting process by utilizing the PSI feature, allows the calculation of votes and results with only one semi-honest center participating, eliminates the unrealistic model settings required by the original electronic voting scheme. At the same time, verifying whether a voter votes correctly does not depend on non-interactive zero-knowledge proofs. In addition to the aggregated voting with privacy protection function, the protocol provided by the present invention also has a wide range of potential applications. The electronic voting protocol can be used in any privacy-protected aggregation scenario, including the aggregation of commercial data, health data, critical infrastructure data, privacy-protected consensus building, model update of industrial control decisions or federated learning.
[0088] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made therein without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A verifiable universal electronic voting method based on privacy set intersection, characterized in that: The method comprises the following steps: S1, initialization phase: S101. Generate initialization parameters. The election agency will generate the necessary parameters for the election and publish them on the bulletin board, including the list of candidates to be elected, the list of eligible voters, and security parameters; S102. Each voter P i Run the ElGamal encryption algorithm to generate the corresponding private key El.Gen(λ)=sk i ∈Z q , calculate the public key based on the generated private key Private key sk i The corresponding public key is pk i , each voter P i Put your identity and public key (i, pk i ) posted on a notice board; S103. The election agency aggregates the voters' public keys on the bulletin board into a joint public key Finally, the public parameters are published on the bulletin board; S2, Voting Stage: S201. The election body generates its own ballot paper EA , and randomly shuffle the order; S202, Voter P i According to the candidate list C={C1,C2,…,C m }Generate your own ballot and give the candidates corresponding scores; S203, Voter P i Run the ElGamal encryption algorithm to encrypt the score to obtain the score ciphertext, and generate the corresponding symmetric encryption key according to the candidate entry, run the symmetric encryption to encrypt the score ciphertext to obtain the double encrypted ciphertext, and associate the score with the candidate at the ciphertext level; S204, sending the score ciphertext and the double-encrypted ciphertext to the election agency, and using the privacy set intersection technology based on the Diffie-Hel lman key agreement protocol to share the symmetric encryption key with the election agency; S3, vote counting stage: S301. After receiving the ciphertext, the election agency runs the symmetric encryption decryption algorithm to obtain the score ciphertext; S302, the election agency aggregates the score ciphertext, and then uses the joint public key to decrypt to obtain the vote count result, generates the election result according to the voting rules, and generates a zero-knowledge proof of the election result; S303, publishing the election results and the corresponding zero-knowledge proof on the bulletin board; S4, Public Verification Phase: All participants verify the accuracy of the counting process and the validity of the election results, and external auditors check zero-knowledge proofs to confirm the results or re-aggregate the votes; S5. Ballot format verification: Election bodies verify the legitimacy of each ballot, and if a ballot is found to be illegal, the vote counters can take it back and use the taken back ballot as evidence of the voter's dishonesty.
2. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In the step S101, the initialization parameters include the candidate list C = {C1, C2, ..., C m }, the election start and end time, the list of voters who meet the voting conditions P = {P1, P2, ..., P n }, security parameter λ, hash function H:{0,1} * →Z q , voting rules, the election body generates the CRS required for Groth16SNARK zero-knowledge proof based on the security parameter λ s .
3. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S203, for j∈[m], voter P i For Candidate C j The score cast is The voter needs to encrypt the score with the public key generated in step S1 Generate the fractional ciphertext, then voter P i Use the random number r that has been pre-generated during the initialization phase i and the candidate entry y on its ballot j Generate symmetric encryption keys The voter then uses symmetric encryption to encrypt the ciphertext of the previous score 4. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In the step S301, W j Represents each voter's opinion on candidate C j The aggregate ciphertext of the voted scores.
5. According to claim 1, a verifiable universal electronic voting method based on privacy set intersection is characterized in that: In step S4, the accuracy judgment expression of zero-knowledge proof is: Verify(CRS VK ,f res (v1,v2,…,v m ),π)→0 / 1.
6. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S5, for the PLURALITY voting rule, when When the vote score To be legal, the score must meet When the election authority or any outside observer has doubts about the ballot submitted by the voter, the election authority calculates the product If voters vote honestly, the product of the above formula will be 0. In order to prevent voters from voting all 0, the election agency needs to check the total score and make sure the total is 1.
7. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S5, for the VETO rule, if the election authority or any external observer has doubts about the ballot submitted by the voter, the election authority needs to check the product of each item on the ballot. Is it equal to 0? Finally, check the sum of the vote scores.
8. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S5, for the APPROVAL rule, voters can only cast K votes with a score of 1, and all other candidates cast 0. The election agency detects the sum of the voter's vote scores. At the same time, check the product S of the voter's vote score i ·(S i -1)·(S i -2)·····(S i -K), when the product of the above formula is 0, the voter's vote is legal, and any result other than 0 will prove that P i Cheating.
9. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S5, for the RANGE rule, the single score of the vote When the ballot is legitimate, the election authority detects a polynomial product If and only if the polynomial product is 0, the electoral body accepts the score of the votes is correct.
10. A verifiable universal electronic voting method based on privacy set intersection according to claim 1, characterized in that: In step S5, for the BORDA rule, the correct voting form requires the following two conditions: For the test of equation (1), the above method is used. For the verification of equation (2), the calculation is Election body in domain Z q Generate a random secret element in , denoted as r j,l ,j≠l∈[m], and then perform the product operation, that is, In r j,l ≠0, the product of the above formula If and only if Completed without revealing about Verify the correctness of the ballot format without the required information.
Citation Information
Patent Citations
Block chain-based electronic voting method capable of verifying fairness
CN114255034A
Time-controlled homomorphic encryption electronic voting method and system based on Paillier algorithm
CN116886258A