Decentralized electronic voting system operating efficiently in environment with multiple candidates

WO2024205182A3PCT designated stage expired Publication Date: 2025-06-19KOREA UNIV RES & BUSINESS FOUND +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/003749
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-03-30
Filing Date
2024-03-26
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing decentralized electronic voting systems face inefficiencies in vote counting, especially when dealing with a large number of candidates, due to exponential computation increases, limiting their applicability to simple yes-or-no voting scenarios.

Method used

A decentralized electronic voting method that allows voters to perform self-tallying using the encrypt-then-cancel rule and zero-knowledge proof technology, enabling efficient vote counting without relying on a separate trust agency, by generating secret and public keys, encrypting votes, and using non-interactive zero-knowledge proofs to verify votes, thereby reducing computational complexity.

Benefits of technology

This approach dramatically reduces the computational burden for vote counting, making it feasible in environments with multiple candidates, and ensures the integrity and transparency of the voting process by allowing anyone to verify the results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024003749_19062025_PF_FP_ABST
    Figure KR2024003749_19062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a decentralized electronic voting system and method which operate efficiently in an environment with multiple candidates. The electronic voting method is performed by a voter's terminal and comprises the steps of: agreeing on (G, g) for a group (G) of prime numbers (p) and a generator (g) of the group (G); generating a secret voting key and a public voting key and publishing the public voting key; generating encrypted votes and encrypted proofs for multiple candidates; publishing the encrypted votes; publishing the encrypted proofs; and calculating the number of votes in favor of each of the multiple candidates on the basis of the votes of all the voters.
Need to check novelty before this filing date? Find Prior Art

Description

A decentralized electronic voting system that operates efficiently in an environment with multiple candidates.

[0001] The present invention relates to a decentralized electronic voting system, and more specifically, to a decentralized electronic voting system in which all voters participating in a vote can vote and count votes on their own without a separate trust institution, and in which anyone can verify that all voters have voted legitimately and that the results of the counting are correct.

[0002] Anonymous voting is an essential means of gathering the opinions of members of a democratic society. With the development of the Internet, various electronic voting systems utilizing cryptography to ensure security and efficiency have been proposed, resulting in significant improvements in cost and time compared to traditional anonymous voting using paper ballots. However, many early electronic voting systems traditionally operated by encrypting votes and relying on a separate trusted authority to count them. A critical drawback of this voting method is the existence of a separate authority, requiring all voters to trust this authority. To address this shortcoming, threshold cryptography can be used to distribute trust in a single trusted authority across multiple authorities. However, these voting systems also require the assurance that these authorities will not collude.

[0003] To address this trust issue, a voting system supporting self-tallying has been developed. A voting system supporting self-tallying eliminates the need for a separate trusted authority for vote counting by allowing anyone to count the votes from encrypted ballots made public to all voters. Key technologies for implementing a voting system supporting self-tallying include the encrypt-then-cancel rule and zero-knowledge proof. Voters can encrypt their own ballots using the encrypt-then-cancel rule and simultaneously count them by removing the random numbers used for encryption from the encrypted ballots made public to other voters. Furthermore, all voters use zero-knowledge proof technology to prove that they have encrypted their ballots correctly without exposing their own votes.

[0004] Most real-world voting systems typically involve a large number of candidates, making it crucial to minimize the costs associated with expanding the number of candidates and thereby increase efficiency. Furthermore, with the advancement of blockchain technology, the importance of decentralized systems is growing in various fields, including cryptocurrencies. Consequently, extensive research is being conducted on electronic voting systems that support self-counting. However, currently known electronic voting systems that support self-counting face limitations: the computational burden required for counting increases exponentially with the number of candidates. Consequently, these systems are limited to extremely limited situations, such as for-or-against voting. Therefore, improving the efficiency of vote counting in decentralized voting systems that support self-counting is a critical challenge that must be addressed.

[0005] The technical task of the present invention is to provide a decentralized electronic voting system that operates efficiently in an environment with multiple candidates.

[0006] According to one embodiment of the present invention, a decentralized electronic voting method that operates efficiently in an environment with multiple candidates is an electronic voting method performed by a voter's terminal, the method comprising the steps of: agreeing on a group (G) for a prime number (p) and (G,g) for a generator (g) of the group (G); generating a secret voting key and a public voting key and disclosing the public voting key; generating encrypted ballots and encrypted proof ballots for a plurality of candidates; disclosing the encrypted ballots; disclosing the encrypted proof ballots; and calculating the number of votes in favor of each of the plurality of candidates based on the ballots of all voters.

[0007] According to the decentralized electronic voting system and method according to an embodiment of the present invention, a decentralized electronic voting technique that operates efficiently even in an environment with multiple candidates can be provided.

[0008] Additionally, compared to existing techniques, it has the effect of drastically reducing the amount of computation required for counting votes.

[0009] In order to more fully understand the drawings cited in the detailed description of the present invention, a detailed description of each drawing is provided.

[0010] FIG. 1 is a flowchart illustrating an electronic voting method according to one embodiment of the present invention.

[0011] Specific structural or functional descriptions of embodiments according to the concept of the present invention disclosed in this specification are merely illustrative for the purpose of explaining embodiments according to the concept of the present invention, and embodiments according to the concept of the present invention may be implemented in various forms and are not limited to the embodiments described in this specification.

[0012] Embodiments according to the concept of the present invention may have various modifications and take various forms, and thus, embodiments are illustrated in the drawings and described in detail herein. However, this is not intended to limit embodiments according to the concept of the present invention to specific disclosed forms, but rather includes all modifications, equivalents, or alternatives falling within the spirit and technical scope of the present invention.

[0013] While terms such as "first" or "second" may be used to describe various components, these components should not be limited by these terms. These terms are only intended to distinguish one component from another. For example, a first component may be referred to as a "second component," and similarly, a second component may be referred to as a "first component," without departing from the scope of the present invention.

[0014] When a component is referred to as being "connected" or "connected" to another component, it should be understood that it may be directly connected or connected to that other component, but that there may be other components in between. Conversely, when a component is referred to as being "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between. Other expressions that describe the relationship between components, such as "between" and "directly between" or "adjacent to" and "directly adjacent to", should be interpreted similarly.

[0015] The terminology used herein is only used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, it should be understood that the terms "comprises" or "has" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in this specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0016] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and will not be interpreted in an idealized or overly formal sense unless explicitly defined herein.

[0017] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings attached to this specification. However, the scope of the patent application is not limited or restricted by these embodiments. The same reference numerals in each drawing represent the same components.

[0018] First, as basic knowledge for the present invention, the Encrypt-then-cancel rule and the Decision Diffie-Hellman (DDH) assumption are explained.

[0019] Encrypt-then-cancel rule

[0020] The idea of ​​post-encryption elimination was first introduced in the work of F. Hao et al. (F. Hao and P. Zieli'nski, “2-round anonymous veto protocol,” in International Workshop on Security Protocols. Springer, 2006, pp. 202-211.) to design a system that can exercise veto anonymously.

[0021] In the system introduced in the study by F. Hao et al., the result was 0 or 1 depending on whether all participants did not exercise the veto or whether at least one participant exercised the veto, whereas in the study by F. Hao et al. (F. Hao, PY Ryan, and P. Zieli'nski, “voting by two-round public discussion,” IET Information Security, vol. 4, no. 2, pp. 62-67, 2010.), it was made to be usable not only for voting (how many votes were in favor and how many were against), but also in a general voting system that elects one candidate in an environment with multiple candidates.

[0022] The post-encryption elimination method is performed in the following order for n participants and each user's data to be hidden.

[0023] 1. A list that assigns an order to all participants (P1,P2,…,P n ), and all voters agree on a group G for large primes p that satisfy the DDH assumption and a generator g of the group (G,g).

[0024] 2. Each participant is a secret key Extract .

[0025] 3. Is Using public key Calculate and disclose.

[0026] 4. uses the public key disclosed by all participants except the participant himself. is calculated as follows.

[0027]

[0028] 5. is the data you want to hide your own secret key Wow, calculated above By using It is encrypted and made public.

[0029] 6. Encrypted data disclosed by all participants By using Calculate. At this time, Table 1 (when n=5, By the sign of are all cleared to 0 This is established.

[0030] 7. Is Satisfying The sum of the data of all participants was calculated through a census ( ) can be obtained.

[0031] DDH (Decision Diffie-Hellman) assumption

[0032] decimal About the danger In-gun , Constructor of , and About tuples ( , , , ) is given, The problem of deciding whether something is real or not is called the DDH problem.

[0033] We define the DDH hypothesis as holding if the probability that a probabilistic-polynomial-time adversary can solve the DDH problem is extremely small.

[0034] Below, the notations used in this specification are explained.

[0035] - a∥b: concatenation of strings a and b (for example, if a=110 and b=101, a∥b is 110101)

[0036] - [k]: set of integers {1,2,…,k}

[0037] - : two sets and The difference of sets (e.g., = {1,2,3,4} If = {2,4} = {1,3})

[0038] - : set of integers {0,1,2,…,p-1}

[0039] - : A cryptographically secure hash function. It takes an arbitrary string as input. Assuming that it outputs

[0040] - n: total number of voters

[0041] - k: total number of candidates

[0042] - : th voter

[0043] - : th candidate

[0044] - : go As a vote to be cast, set it to 1 if in favor and 0 if against. Satisfy

[0045] The objects that make up the decentralized electronic voting system are (voters) and (candidate). That is, the decentralized electronic voting system may be composed of multiple terminals, each corresponding to a plurality of voters. Any one of the multiple terminals may communicate with another one of the multiple terminals via a predetermined wired or wireless communication network. In addition, each of the multiple terminals may refer to a computing device including at least a processor and / or memory, such as a smart phone, a mobile phone, a personal computer (PC), a tablet PC, a head-mounted device (HMD), a smart watch, smart glasses, a laptop, etc. Accordingly, the computing device may be referred to as a terminal for pre-election voting, an electronic voting device, etc.

[0046] The overall protocol for a decentralized electronic voting method consists of the Setup, Round 1, Round 2, and Self-Tallying stages, and each algorithm and protocol is described below. Furthermore, a flowchart of an electronic voting method according to one embodiment of the present invention is illustrated in Figure 1. At least some of the steps of the decentralized electronic voting method may be understood as the operations of a processor in a computing device.

[0047] Setup.

[0048] A list that assigns the order of each voter and candidate for n (n is a natural number greater than or equal to 2) voters and k (k is a natural number greater than or equal to 2) candidates ( , , … , )and ( , , … , ) and all voters (which may mean the terminals of voters) are large prime numbers that satisfy the DDH assumption. military for and the creator of that group About ( , ) agree on. That is, all voters ( , ) can be assumed to have been agreed upon.

[0049] Round 1.

[0050] 1. Each voter (may refer to the voter's terminal) is all k private voting keys for Extract (which may be understood as selecting or generating).

[0051] 2. is all About Using public voting keys Calculate .

[0052] 3. is all About your secret voting key We prove that we know using the non-interactive zero-knowledge (NIZK) protocol. The proof value of the zero-knowledge protocol is It can be expressed as and is generated through the process below. In this regard, Table 1 shows the public voting keys disclosed by n voters.

[0053] 3.1. Any Select .

[0054] 3.2. Calculate .

[0055] 3.3. Cryptographic Hash Functions By using Calculate .

[0056] 3.4. Calculate .

[0057] 3.5. Proof value Set to .

[0058] 4. is all About and is disclosed.

[0059] 5. All voters except themselves can vote for all candidates, i.e. and All that satisfy ( ) about To verify if it is valid Check if this holds. If it holds, move on to the next step. If even one of them does not hold, stop the protocol and output 0.

[0060] 6. All voters except for the candidate use the public voting key disclosed by the candidate. and is calculated as follows.

[0061]

[0062]

[0063] [Table 1]

[0064]

[0065] Round 2.

[0066] 1. Each voter is all About Only one of the (which may be named as an event ticket) votes in favor (in this case, = 1) and all other votes are against (in this case, = 0) to set your secret voting key Wow, calculated above and By using (which may be named as (encrypted) hansei table) and Computes (which may be named as an (encrypted) proof table).

[0067] 2. is all About used to calculate We prove that is 0 or 1 using a non-interactive zero-knowledge proof protocol. The proof value of the zero-knowledge protocol is It can be expressed as and is generated through the process below.

[0068] 2.1. If = 1, follow steps 2.1.1.~2.1.5. below, otherwise go to 2.2.

[0069] 2.1.1. Any , , ∈ Select .

[0070] 2.1.2. class Calculate.

[0071] 2.1.3. class Calculate.

[0072] 2.1.4. Cryptographic Hash Functions By using Calculate .

[0073] 2.1.5. and Calculate.

[0074] 2.2. If = 0, follow steps 2.2.1.~2.2.6. below.

[0075] 2.2.1. Any , , ∈ Select .

[0076] 2.2.2. class Calculate.

[0077] 2.2.3. class Calculate.

[0078] 2.2.4. Using the cryptographic hash function H Calculate .

[0079] 2.2.5. and Calculate.

[0080] 2.3. Proof value Set to .

[0081] 3. is all About and is disclosed.

[0082] 4. is all About and The same for calculating and The fact that was used is proven using a non-interactive zero-knowledge proof protocol. The proof value of the zero-knowledge proof protocol is It can be expressed as and is generated through the process below.

[0083] 4.1. Any , ∈ Select .

[0084] 4.2. and Calculate .

[0085] 4.3. Cryptographic Hash Functions By using Calculate .

[0086] 4.4 and Calculate.

[0087] 4.5. Proof value Set to .

[0088] 5. is all About and is disclosed.

[0089] 6. All voters except themselves can vote for all candidates, i.e. and For all (j,i) satisfying and To verify validity, check whether 6.1. and 6.2. below hold. If all hold, proceed to the next step. If even one of them does not hold, stop and output 0.

[0090] 6.1.

[0091] 6.2.

[0092] 7. is all voters except for himself, that is, all About Check if it holds. If all of them hold, move on to the next step. If even one of them does not hold, stop and output 0.

[0093] As mentioned above, and Verify and formula By checking whether the one-man-one-vote rule is established, the one-man-one-vote rule can be verified.

[0094] Self-Tallying.

[0095] 1. Each voter is all About Calculate .

[0096] 2. is all About Satisfying is calculated through a comprehensive survey. In other words, by solving the discrete logarithm problem. can be calculated. Here, can mean the number of votes in favor of the i-th candidate.

[0097] The devices described above may be implemented as hardware components, software components, and / or a collection of hardware components and software components. For example, the devices and components described in the embodiments may be implemented using one or more general-purpose computers or special-purpose computers, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor (DSP), a microcomputer, a field programmable array (FPA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing instructions and responding to them. The processing device may execute an operating system (OS) and one or more software applications running on the operating system. Furthermore, the processing device may access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing device is sometimes described as being used alone; however, one of ordinary skill in the art will recognize that the processing device may include multiple processing elements and / or multiple types of processing elements. For example, a processing unit may include multiple processors, or a processor and a controller. Other processing configurations, such as parallel processors, are also possible.

[0098] Software may include a computer program, code, instructions, or a combination of one or more of these, and may configure a processing device to perform a desired operation or command the processing device, independently or collectively. The software and / or data may be permanently or temporarily embodied in any type of machine, component, physical device, virtual equipment, computer storage medium or device, or transmitted signal wave to be interpreted by the processing device or to provide instructions or data to the processing device. The software may be distributed over networked computer systems and stored or executed in a distributed manner. The software and data may be stored on one or more computer-readable recording media.

[0099] The method according to the embodiment may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiment or may be those known to and usable by those skilled in the art of computer software. Examples of the computer-readable recording medium include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specially configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of the program commands include not only machine language codes generated by a compiler but also high-level language codes that can be executed by a computer using an interpreter or the like. The hardware devices described above may be configured to operate as one or more software modules to perform the operations of the embodiment, and vice versa.

[0100] Although the present invention has been described with reference to the embodiments illustrated in the drawings, these are merely exemplary, and those skilled in the art will understand that various modifications and equivalent other embodiments are possible from the described techniques. For example, appropriate results can be achieved even if the described techniques are performed in a different order than the described method, and / or components of the described systems, structures, devices, circuits, etc. are combined or combined in a different form than the described method, or are replaced or substituted with other components or equivalents. Therefore, the true technical protection scope of the present invention should be determined by the technical spirit of the appended claims.

Claims

1. In an electronic voting method performed by a voter's terminal, decimal( ) for the military ( ) and the above group ( )'s constructor( ) for ( ) to reach an agreement; A step of generating a secret voting key and a public voting key and disclosing the public voting key; A step of generating an encrypted event ticket and an encrypted certificate ticket for multiple candidates; A step of disclosing the above encrypted event ticket; A step of disclosing the encrypted certificate; and Comprising a step of calculating the number of votes in favor of each of the multiple candidates based on the event tables of all voters, Electronic voting method.

2. In paragraph 1, The secret voting key of the voter who is the lth voter (l is any natural number) among all voters for the ith candidate (i is a natural number less than or equal to k) among the kth candidates (k is a natural number greater than or equal to 2) is And, The above public voting key is person, Electronic voting method.

3. In paragraph 2, The above disclosed steps are: A step of proving that the secret voting key is known for all i using a first non-interactive zero-knowledge (NIZK) proof, The above-mentioned disclosing step further discloses the first proof value of the first NIZK of the upper limb, Electronic voting method.

4. In paragraph 3, The above first proof value ( )silver, Any The process of selecting, The process of calculating, Cryptographic hash function( ) using The process of calculating, The process of calculating , and The above first proof value Generated through the process of setting up, Electronic voting method.

5. In paragraph 4, After the above disclosure step, Further comprising a step of verifying the validity of the first proof value of all voters except the above voter, The step of verifying the validity of the above first proof value is To determine whether or not it is established, Electronic voting method.

6. In paragraph 5, After the step of verifying the validity of the above first proof value, , and further comprising the step of calculating, Electronic voting method.

7. In paragraph 6, The above encrypted event ticket is And, The above encrypted certificate is person, Electronic voting method.

8. In paragraph 7, The step of disclosing the above encrypted event ticket is: used to calculate Further revealing the second proof value of the second non-interactive zero-knowledge proof to prove that is 0 or 1. Electronic voting method.

9. In paragraph 8, The above second proof value is, = 1, any , , ∈ Select , class and calculate, class , and calculate the cryptographic hash function By using Calculate, and and calculate, = 0, any , , ∈ Select , class and calculate, class , and calculate the cryptographic hash function By using Calculate, and By calculating, The above second proof value ( ) to create, Electronic voting method.

10. In paragraph 9, The step of disclosing the encrypted certificate further discloses the third proof value of the third non-interactive zero-knowledge proof to prove that the same secret voting key and certificate were used to calculate the encrypted certificate and the encrypted event certificate. Electronic voting method.

11. In paragraph 10, The third proof value above is, Any , ∈ The process of selecting, and The process of calculating, Using the cryptographic hash function H The process of calculating, and The process of calculating , and The above third proof value Generated through the process of setting up, Electronic voting method.

12. In paragraph 11, After the step of disclosing the above encrypted certificate, Further comprising a step of verifying the validity of the second proof value and the third proof value of all the voters above, The step of verifying the validity of the second proof value and the third proof value is: and To determine whether or not it is established, Electronic voting method.

13. In paragraph 12, The step of verifying the validity of the second proof value and the third proof value is: Further judging whether or not it is established, Electronic voting method.

14. In paragraph 13, The step of calculating the number of votes in favor is: For all i∈[k] Steps to calculate, and For all i∈[k] Satisfying comprising the steps of calculating , Electronic voting method.

Citation Information

Patent Citations

  • Electronic voting management method

    JP2022107556A

  • A self-verifiable blockchain electronic voting management method

    KR102169695B1

  • Electronic voting system using blockchain and electronic voting method using blockchain

    KR102186029B1

  • APPARATUS OF SPRAYING LIQUID BASED ON IoT

    KR102222745B1

  • A fecal image analysis system and a method therefor

    KR102599894B1