System and methods for enabling privacy and transparency in electoral bonds using cryptography and blockchain

The system addresses the lack of transparency and privacy in electoral bonds by using zero-knowledge proof and homomorphic encryption to manage and secure electoral bonds, enhancing trust and transparency in the electoral process.

WO2025248311A1PCT designated stage Publication Date: 2025-12-04CENT FOR DEV OF ADVANCED COMPUTING
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/050702
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-31
Filing Date
2025-01-23
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing electoral bond systems in India lack transparency and privacy, leading to concerns about donor anonymity and the right to information, which undermines trust in democratic governance.

Method used

A system utilizing zero-knowledge proof and homomorphic encryption to securely manage electoral bonds, ensuring donor privacy while maintaining transparency by shuffling and encrypting bonds, and using a blockchain to verify transactions and prevent double-spending.

Benefits of technology

Enhances transparency and trust in the electoral bond process by ensuring donor anonymity and verifying transactions, while allowing authorized entities to access information, thus strengthening democratic governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025050702_04122025_PF_FP_ABST
    Figure IB2025050702_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to systems (102) and methods for enabling privacy and transparency in electoral bonds using cryptography and blockchain. The cryptographic scheme is incorporated to enable donors privacy and citizens right to information in the electoral bond process. The proposed system (102) leverages cryptographic primitives such as zero-knowledge proof and homomorphic encryption simultaneously. The zero-knowledge proof enables verifiable computation which lets users perform computations privately and prove the validity of the same using zero-knowledge proof. The homomorphic encryption lets participants perform computations on encrypted data. System (102) leverages smart contracts to ensure the transparency of the functionality thereby further strengthening the trust in the system.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHODS FOR ENABLING PRIVACY AND TRANSPARENCY IN ELECTORAL BONDS USING CRYPTOGRAPHY AND BLOCKCHAIN FIELD OF INVENTION

[0001] The embodiments of the present disclosure generally relate to cryptographic systems. More particularly, the present disclosure relates to systems and methods for enabling privacy and transparency in electoral bonds using cryptography mechanisms such as zero- knowledge proof and homomorphic encryption and blockchain. BACKGROUND OF THE INVENTION

[0002] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0003] Electoral bond refers to a financial instrument for political funding in India from 2017 to early 2024. The objectives of introducing electoral bonds were primarily to curb the usage of cash in political funding and to maintain the donor’s identity anonymous to prevent them from possible political influence. The said bonds are essentially the bearer instruments which bear no information of the owner and can be claimed by any legitimate beneficiary party which holds the instrument. The electoral bonds can be purchased by any Indian citizen or an organization registered in India after going through the requisite KYC verification process. Unlike traditional donations, the electoral bonds can be purchased only from authorized branches of the State Bank of India in specific denominations of one thousand, ten thousand, one lakh, ten lakh or one crore Indian Rupees. The electoral bonds can be purchased only through cheque or digital payments. Currently, the electoral bonds are distinctively special to India, other countries have their own unique systems and processes in place to finance political parties which serve the same purpose. The systems are designed and implemented with varying assumptions and regulatory requirements.

[0004] Although the intent of the electoral bonds was noble, since their introduction, they have been a subject of controversies. The electoral bonds have been criticized primarily for the lack of transparency to citizens and for providing an unfair advantage to the ruling party by obscuring the identities of the donors from everyone but the State Bank of India. The supporters of the electoral bonds emphasize the importance of donor’s privacy to preventdonors from any possible political reprisal or fear. Amongst these controversies and the legal petitions, eventually, in February 2024, the electoral bonds were deemed unconstitutional by the Supreme Court of India for violating the right to information of voters.

[0005] One of the existing technology discloses a scheme to let users participate in electronic voting by proving their eligibility to vote without revealing their identity. Another existing technology discloses the importance of an appropriate donation platform which can keep the donor’s information secret. Some of the factors which reduce the donor’s confidence are the lack of required privacy, trustful insiders, misutilization of donations and mismanagement of resources.

[0006] Another existing technology discloses a blockchain-based rice-donation system using the Internet of Things for orphanages in Indonesia. The participants are primarily the service providers, the donors and the rice suppliers. Donors donate rice through service providers to the rice suppliers. Rice suppliers transfer the rice donation to the orphanages. Further, another existing technology discloses a blockchain-based donation system to address the scenario where donors want to ensure that the donation is being spent as expected. The participating entities in the system are the donors, the charitable foundations and the recipients. The solution uses the blockchain to ensure that all transactions are transparent, immutable and public.

[0007] Although researchers have addressed some of the existing shortcomings such as donor privacy, some of the challenges are still to be addressed such as donor privacy while still maintaining the citizen’s right to information. Designing such a scheme, which can reconcile both the privacy and the transparency requirements necessitates careful consideration of cryptographic primitives.

[0008] Therefore, there is a need in the art to provide robust, reliable, and efficient systems and methods for providing better transparency by using blockchain to enable premitives such as zero-knowledge proof and homomorphic encryption which can help in strengthening and reinstating trust in the democratic governance of the country. OBJECTS OF THE PRESENT DISCLOSURE

[0009] Some of the objects of the present disclosure, which at least one embodiment herein satisfies, are as listed herein below.

[0010] An object of the present disclosure provide systems and methods for ensuring that the requirements of the stakeholders including donors, beneficiaries, banks, service providers and citizens are met.

[0011] Another object of the present disclosure provide systems and methods for effectively reconciling the conflicting requirements of donor’s privacy and citizen's right to information.

[0012] Another object of the present disclosure proposes blockchain technology to facilitate tamper-proof and record-keeping transactions which can ensure that donations reach the intended recipients thereby increasing transparency, accountability and trust in the system.

[0013] Another object of the present disclosure proposes leverages advanced cryptographic primitives such as zero-knowledge proof and homomorphic encryption to ensure privacy to donors while still maintaining transparency to citizens.

[0014] Yet another object of the present disclosure strengthens the trust in the electoral bond process which further strengthens the trust in the democracy at large. SUMMARY

[0015] The present disclosure provides a system for securely managing a set of electoral bonds, the system includes one or more processors operatively coupled to a financial institution and a service provider, the one or more processors coupled to a memory, with the memory storing instructions executable by the one or more processors to generate the set of electoral bonds that are shuffled and encrypted. The generation is performed collaboratively by the financial institution and the service provider, with each electoral bond being associated with a predefined denomination. The system processes requests from one or more donors to purchase a corresponding set of electoral bonds of the predefined denomination, wherein the one or more donors are verified through a know your customer (KYC) process, and the purchased electoral bonds are marked as sold to respective donors. The system enables the one or more donors to transfer the purchased electoral bonds to one or more beneficiary entities. The system further facilitates redemption of the transferred electoral bonds by the one or more beneficiary entities through submission to the financial institution, wherein the validity of the transferred electoral bonds and the one or more beneficiary entities is verified, marking the transferred electoral bonds as redeemed upon successful verification. Zero- knowledge proof and homomorphic encryption are implemented to ensure verifiable computation for each transaction, maintain unlinkability between the one or more donors and the one or more beneficiary entities, and provide transparency to authorized entities.

[0016] In one embodiment, each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted groupelements corresponding to each electoral bond, wherein the homomorphic encryption is a ElGamal encryption. In another embodiment, the one or more processors shuffle and re- encrypt the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed. The one or more processors facilitate anonymity of the one or more donors by maintaining mapping between the one or more donors and corresponding bond identifiers anonymous. Similarly, the one or more processors facilitate the anonymity of the one or more beneficiary entities by maintaining the mapping between the one or more beneficiary entities and the one or more donors anonymous. The one or more processors facilitate the transparency to the authorized entities by enforcing both the financial institution and the service provider to provide information to a Election Commission of India (ECI) which aggregate information and provide to the authorized entities.

[0017] The one or more processors are also configured to initialize the status of each electoral bond as available, modify the status of the corresponding electoral bonds to sold upon confirmation of purchase by the one or more donors, and modify the status of the corresponding electoral bonds to redeemed upon confirmation of a valid redemption request by the one or more beneficiary entities. Additionally, the one or more processors prevent double-spending of the set of electoral bonds by marking the corresponding electoral bond as redeemed upon its first use.

[0018] Furthermore, the processors ensure the prevention of double-spending by marking the redeemed bonds as “spent,” verifying redemption requests by checking the status of the set of electoral bonds, and ensuring that only the first valid redemption request is accepted, rejecting any subsequent redemption attempts.

[0019] Various objects, features, aspects, and advantages of the inventive subject matter will become more apparent from the following detailed description of preferred embodiments, along with the accompanying drawing figures in which like numerals represent like components. BRIEF DESCRIPTION OF DRAWINGS

[0020] The accompanying drawings, which are incorporated herein, and constitute a part of this invention, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present invention. Some drawings mayindicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that the invention of such drawings includes the invention of electrical components, electronic components, or circuitry commonly used to implement such components.

[0021] FIG. 1 illustrates an exemplary network architecture in which or with which the system of the present disclosure can be implemented for enabling privacy and transparency in electoral bonds using cryptography and blockchain, in accordance with an embodiment of the present disclosure.

[0022] FIG. 2A illustrates an exemplary block diagram representation of shuffled and unshuffled set of encrypted bonds, in accordance with an embodiment of the present disclosure.

[0023] FIG. 2B illustrates an exemplary block diagram representation of electoral bonds, in accordance with an embodiment of the present disclosure when some of the bonds are available for sale, some are donated and some are credited.

[0024] FIG. 3 illustrates an exemplary representation of a method for enabling privacy and transparency in electoral bonds using zero-knowledge proof, homomorphic encryption and blockchain, in accordance with an embodiment of the present disclosure.

[0025] FIG. 4 illustrates an exemplary computer system in which or with which embodiments of the present invention can be utilized, in accordance with embodiments of the present disclosure.

[0026] The foregoing shall be more apparent from the following more detailed description of the invention. DETAILED DESCRIPTION OF INVENTION

[0027] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address all of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein.

[0028] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, theensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the invention as set forth.

[0029] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail to avoid obscuring the embodiments.

[0030] Also, it is noted that individual embodiments may be described as a process which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0031] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive—in a manner similar to the term “comprising” as an open transition word—without precluding any additional or other elements.

[0032] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present invention. Thus, the appearances of the phrases “in oneembodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0033] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.

[0034] The present disclosure provides a system for securely managing a set of electoral bonds, the system includes one or more processors operatively coupled to a financial institution and a service provider, the one or more processors coupled to a memory, with the memory storing instructions executable by the one or more processors to generate the set of electoral bonds that are shuffled and encrypted. The generation is performed collaboratively by the financial institution and the service provider, with each electoral bond being associated with a predefined denomination. The system processes requests from one or more donors to purchase a corresponding set of electoral bonds of the predefined denomination, wherein the one or more donors are verified through a Know Your Customer (KYC) process, and the purchased electoral bonds are marked as sold to respective donors. The system enables the one or more donors to transfer the purchased electoral bonds to one or more beneficiary entities. The system further facilitates redemption of the transferred electoral bonds by the one or more beneficiary entities through submission to the financial institution, wherein the validity of the transferred electoral bonds and the one or more beneficiary entities is verified, marking the transferred electoral bonds as redeemed upon successful verification. Zero- knowledge proof and homomorphic encryption are implemented to ensure verifiable computation for each transaction, maintain unlinkability between the one or more donors and the one or more beneficiary entities, and provide transparency to authorized entities.

[0035] In one embodiment, each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted group elements corresponding to each electoral bond, wherein the homomorphic encryption is aElGamal encryption. In another embodiment,. the one or more processors shuffle and re- encrypt the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed.

[0036] The one or more processors facilitate anonymity of the one or more donors by maintaining mapping between the one or more donors and corresponding bond identifiers anonymous. Similarly, the one or more processors facilitate the anonymity of the one or more beneficiary entities by maintaining the mapping between the one or more beneficiary entities and the one or more donors anonymous. The one or more processors are also configured to initialize the status of each electoral bond as available, modify the status of the corresponding electoral bonds to sold upon confirmation of purchase by the one or more donors, and modify the status of the corresponding electoral bonds to redeemed upon confirmation of a valid redemption request by the one or more beneficiary entities. Additionally, the one or more processors prevent double-spending of the set of electoral bonds by marking the corresponding electoral bond as redeemed upon its first use. Furthermore, the processors ensure prevention of double-spending by marking the redeemed bonds as “spent,” verifying redemption requests by checking the status of the set of electoral bonds, and ensuring that only the first valid redemption request is accepted, rejecting any subsequent redemption attempts.

[0037] Various embodiments of the present disclosure provide systems and methods for ensuring the requirements of the stakeholders including donors, beneficiaries, banks, service providers and citizens meet their respective rights. The present disclosure provides systems and methods for effectively reconciling the conflicting requirements of donor privacy and citizens right to information. The present disclosure facilitates tamper-proof and record-keeping transactions which can ensure that donations reach the intended recipients thereby increasing transparency, accountability and trust in the system. The present disclosure leverages advanced cryptographic primitives such as zero-knowledge proof and homomorphic encryption to ensure privacy to donors while still maintaining transparency to citizens. The present disclosure strengthens the trust in the electoral bond process which further strengthens the trust in the democracy at large.

[0038] Referring to FIG. 1 illustrates an exemplary network architecture for enabling privacy and transparency in electoral bonds using blockchain (100) (also referred to as network architecture (100)) in which or with which a system (102) of the present disclosure can be implemented, in accordance with an embodiment of the present disclosure. Asillustrated, the exemplary network architecture (100) may be equipped with the system (102) for enabling privacy and transparency in electoral bonds using blockchain with cryptographic primitives such as zero-knowledge proof and homomorphic encryption, to one or more users (106-1, 106-2, …, 106-N) (individually referred to as the user (106) and collectively referred to as the users (106)) associated with one or more secure user devices (108-1, 108-2, …, 108- N) (individually referred to as the user device (108) and collectively referred to as the user devices (108)). The entity (106) may include, a political party, a donor, a financial institution, a service provider, the election commission, a civil society organization, and the like. Further, the system (102) may also be communicatively coupled to one or more user devices (108) via a communication network (104). The communication network (104) may include a wireless network, a wired network, or a combination thereof that can be implemented as one of the different types of networks, such as Intranet, Local Area Network (LAN), Wide Area Network (WAN), Internet, and the like. Further, the communication network (104) may be either a dedicated network or a shared network. The shared network can represent an association of the different types of networks that can use a variety of secure protocols, for example, Hypertext Transfer Protocol Secure (HTTPS), Transmission Control Protocol / Internet Protocol (TCP / IP), Wireless Application Protocol (WAP), and the like. It is assumed that all communications are secured through TLS and all requests are digitally signed by the sender which is verified by the receiver.

[0039] The entity (108) includes a user device with a secure digital wallet capability. In some implementations, the one or more user devices (108) may include, but are not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, a tablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a health monitoring handheld device, a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media-playing device, a portable gaming system, and / or any other type of computing device with wireless communication capabilities, and the like.

[0040] In some implementations, the system (102) may be coupled to a blockchain network (112). While a single blockchain network is shown in FIG. 1, it is understood that multiple blockchain networks may be utilized for secure and traceable fund transfer operation capabilities described herein. The blockchain network (112) may also be operatively coupled to one or more user devices (108) and the computing devices (108) through the communication network (104). As illustrated in FIG. 1, the blockchain network (112) is anillustrative example in accordance with at least one embodiment of the present disclosure. The blockchain network (112) illustrates a simplified blockchain having blocks. The blocks may include a genesis block. Each block may include certain information, such as identification, or hash, that uniquely identifies the block, a timeline identifying previous blocks (e.g., the hash numbers of previous blocks) in chronological order, transactions to record all transfers between a sender and a receiver, and a public key that identifies at least one sender and at least one receiver. The linked blocks, therefore, form a chain where each link, or block, in the chain uniquely identifies a previous link, or block, by including the hash or the prior link, or block. The blockchain network (112), maybe a distributed ledger, or blockchain may be distributed, or replicated, on a network. The distributed ledger may be replicated and maintained on a database within the underlying blockchain network (112). The blockchain network (112) (or decentralized secure transaction ledger) may be maintained by nodes in a distributed network. Although each block of blockchain network (112) / ledger may include differentiated information and may have distinct purposes, each block may include, but are not limited to, communication, a message, information, data, and the like. The blockchain network (112) may be used to send messages, or conduct transactions, between at least two entities through, for example, nodes in a network. By way of non-limiting example, a message in a block of the blockchain network (112) may include a header and contents, and the like. The header may include at least one block ID for block, a nonce value, and an arbitrary number that may be used as a cryptographic hash function. These values and block information may be used in linking blocks together to form a chain.

[0041] Although FIG. 1 shows exemplary components of the network architecture (100), in other implementations, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).

[0042] In some implementations, the system (102) may be a standalone device and may be communicatively coupled to the computing device (not shown in FIG. 1) and / or a centralized server (not shown in FIG.1). In another implementation, the system (102) may be associated with the computing device or the centralized server. The system (102) may be implemented in, but are not limited to, an electronic device, a mobile device, a wireless device, a wired device, a server, and the like. Such server may include, but are not limited to, a standalone server, a remote server, a cloud server, a dedicated server, and the like. In anembodiment, the system (102) may communicate with other devices or the one or more user devices (108), or the blockchain network (112) using the communication network (104). In other embodiments, the system (102) may also communicate via other various protocols and technologies such as Fourth Generation (4G), Fifth Generation (5G), Sixth Generation (6G), New Radio (NR), Bluetooth®, Zigbee, Near Field Communication (NFC), WiFi®, WiMax®, and iBeacon®. In other embodiments, the system (102) may also connect in a wired manner to the devices. Examples of the entity devices may include, but are not limited to, computer monitors, television sets, light-emitting diodes (LEDs), and liquid crystal displays (LCDs).

[0043] In an embodiment, the system (102) may include one or more processors 114 coupled with a memory 116, wherein the memory 116 may store instructions which when executed by the one or more processors may cause the system (102) to provide an ElGamal Encryption along with a Zero-Knowledge Proof of the computation.

[0044] In an embodiment, the ElGamal encryption is a public-key cryptosystem that is based on the difficulty of the discrete logarithm problem and offers homomorphic encryption capabilities. The ElGamal encryption has a homomorphic property, which, in the case of multiple encryptions, makes the order of encryptions irrelevant during decryption. The three primary functions of this cryptosystem are key generation, encryption, and decryption. In the key generation function, a user generates a key pair consisting of a publickey ^p, g, y^ and a private key x, where p is a large prime number, g is a generator of themultiplicative group modulo p and y ൌ g^ ^mod p^. In the encryption function, the system(102) enables encryption of a message. To encrypt message M, a random number r ∈ୖ ℤ୮ischosen and the ciphertext in equation (1) is computed.c^ ൌ g୰^mod p^,cଶ ൌ M. y୰^mod p^--- Equation (1)In the decryption function, the ciphertext ^c^, cଶ^ is decrypted to obtain message in plaintextas indicated in equation (2).M ൌ cଶ. ^c^^^ି^^mod p^--- Equation (2) where ^c^^^ି^is the modular inverse of c^^^mod p^ which can be computed using the private key x.

[0045] In an embodiment, let us consider a binary relation R ൌ ^x, w^, in whichmembership can be determined efficiently in polynomial time. For a given x, w^x^is the setof witnesses such that ^x, w^ ∈ R. A proof of knowledge is a two-party protocol involving aprover P and a verifier V. Both P and V receive a common input x, while P holds a private input w. P aims to convince V that w belongs to w^x^ without disclosing w. Such protocols typically follow a three-round approach which is structured as an ordered triple^m1, c, m2^--- Equation (3) where ^^1 is the commitment generated by the prover, c is a random challenge generated by the verifier and m2 is the prover's final response.

[0046] In an embodiment, the following are the assumptions made by the protocol.Completeness: If w ∈ w^x^ then the verifier will accept with certainty. Special Soundness:Given two interactions between the prover P and verifier V resulting in message flows^m^, c, mଶ^ and ^m^, c′, mᇱଶ ^, where c ് c′, then an element in w^x^ can efficiently becomputed. Honest Verifier Zero-Knowledge: There exists a simulation ^^of the prover that, when given input ^^, generates triples indistinguishable from genuine interactions between an honest prover and verifier. Further, the three-round protocols are used to create proofs of knowledge of elements in different structures. For example, if the prover knows the discretelogarithm x୧, ∃i ൌ 1, 2, 3, (s)he can convince the verifier that (s)he knows one of the discretelogarithms without revealing the exact one. The present disclosure uses such protocols to let users prove that an encryption of an electoral bond’s identifier is an encryption of the identifier from a given set.

[0047] The Chaum-Pedersen protocol is a cryptographic scheme for provingknowledge of the equality of discrete logarithms A ൌ g^భand B ൌ h^మ that enables a prover todemonstrate to a verifier that it possesses knowledge of two discrete logarithms that areequivalent, i.e., x^ ൌ xଶ. This protocol relies on the properties of the discrete logarithmproblem and employs techniques such as commitment schemes and zero-knowledge proofs to ensure the confidentiality and integrity of the information being exchanged. The protocol works as follows.^ Prover selects x^, xଶ ∈ୖ ℤ୯, computes commitments C ^^ ൌ g భand C ^ଶ ൌ h మ and sends thecommitments ^C^, Cଶ^ to the verifier.^ Verifier selects a random challenge c ∈ୖ ℤ୯and sends to the verifier.^ Prover responds with r ൌ xଶ ^ x^. c ^mod q^.^ The verifier accepts the proof if and only if g୰ ൌ C^. Aୡand h୰ ൌ Cଶ. Bୡ.The Chaum-Pedersen protocol is an interactive protocol which is converted to a non- interactive protocol by generating the random challenge c from the hash of the commitmentand the public input values A and B. This paper uses the notation CPZKP^A, B, g, h: x^^ todenote Chaum-Pedersen protocol.

[0048] In an embodiment, the Blockchain is essentially a distributed ledger database which provides secure and immutable data storage. Blockchain consists of a chain of blocks and each block further consists of a set of transactions done on a designated asset. Blockchain is heavily used by most cryptocurrencies such as Bitcoin and Ethereum. Though blockchain is being popularized by cryptocurrencies, its usage has expanded in many other areas such as healthcare, financial services, supply-chain management, etc. Ethereum is another blockchain-based platform with smart contract functionality. All users need to have an Externally Owned Account (EOA) to interact with Ethereum. Smart contracts are self- executing code with state data and member functions known as Application Binary Interfaces (ABI). Smart contracts are written using a programming language such as Solidity, Vyper, Yul and Cairo, compiled into Ethereum Virtual Machine bytecode and deployed on the blockchain. Once deployed, smart contract code becomes immutable. Smart contracts can be accessed through the address in the blockchain where they are deployed. Transactions in Ethereum are digitally signed. Though the source of the transaction can only be an EOA address, the destination of the transaction can either be an EOA address or the smart contract address.

[0049] In an embodiment, the system (102) consists of an electoral bond decentralized application which lets users take actions based on their roles. The users (106) could be a bank, a donor, a beneficiary party, a service provider and the like. The system (102) consists of two smart contracts. An Identity Manager Contract which maintains the identities of the enrolled users and an Electoral Bond Service Provider Contract which provides electoral bond services to the users.

[0050] In an embodiment, the proposed system aims to achieve the following security and privacy requirements. First is the Donor Privacy where the electoral bond should not encode in it the identity of its owner. Second is the Donor and Beneficiary unlinkabilitywhere the participating entities which do not have the necessary right to information, such as the financial institution which issues and redeems the bonds should not be able to link the donor with the beneficiary to which the donation is made. Third is the Transparency to citizens which includes the participating entities which have the necessary right to information, such as the citizens, should be able to know the details of the donors and the beneficiary parties to which the donation is made. Fourth is the Non-repudiation of Electoral Bonds where once an electoral bond is issued, the financial institution should not be able to claim that the specific electoral bond was never issued by the institution. Fifth is the Prevention of double spending which ensures redemption of an electoral bond should not be possible more than once.

[0051] In an embodiment, the system (102) consists of two smart contracts which are deployed by an apex governing body such as Election Commission of India (ECI) – Identity Manager Contract and Electoral Bond Service Provider Contract. Identity Manager Contract lets users enroll in to the system and maintains identities of registered users along with their roles. A user can register himself as an Indian citizen, an Indian organizational body, a designated Electoral Bond Service Provider (EBSP), an ECI, a designated financial institution which can issue and redeem electoral bonds or a beneficiary political party. The primary data members of the contract are cryptParams which contains the cryptographic public parameters, an identities list which maps a user’s EOA address to an Identity structure containing the non-confidential attributes of the user such as role, a users list which contains the EOA addresses of all registered users and the address of the Electoral Bond Service Provider Contract. Each user can be assigned a role of the citizen, the beneficiary, the financial institution, the organization, the donor, the ECI or the EBSP. The methods in the contract include the interfaces to manage users such as registration, updation and deletion of a user which also update the relevant data members appropriately. If a citizen or an organizational body wants to become a donor, it needs to request to become a donor through rqstDonorMembership method. If approved, they are added to the list of donors.Identity Manager Contract lets users enroll in to the system and maintains identities of registered users along with their roles. A user can register himself as an Indian citizen, an Indian organizational body, a designated Electoral Bond Service Provider (EBSP), an ECI, a designated financial institution which can issue and redeem electoral bonds or a beneficiary political party. The primary data members of the contract are cryptParams which contains the cryptographic public parameters, an identities list which maps a user’s EOA address to an Identity structure containing the non-confidential attributes of the user such as role, a userslist which contains the EOA addresses of all registered users and the address of the Electoral Bond Service Provider Contract. Each user can be assigned a role of the citizen, the beneficiary, the financial institution, the organization, the donor, the ECI or the EBSP. The methods in the contract include the interfaces to manage users such as registration, updation and deletion of a user which also update the relevant data members appropriately. If a citizen or an organizational body wants to become a donor, it needs to request to become a donor through rqstDonorMembership method. If approved, they are added to the list of donors. Identity Manager Contract lets users enroll in to the system and maintains identities of registered users along with their roles. A user can register himself as an Indian citizen, an Indian organizational body, a designated Electoral Bond Service Provider (EBSP), an ECI, a designated financial institution which can issue and redeem electoral bonds or a beneficiary political party. The primary data members of the contract are cryptParams which contains the cryptographic public parameters, an identities list which maps a user’s EOA address to an Identity structure containing the non-confidential attributes of the user such as role, a users list which contains the EOA addresses of all registered users and the address of the Electoral Bond Service Provider Contract. Each user can be assigned a role of the citizen, the beneficiary, the financial institution, the organization, the donor, the ECI or the EBSP. The methods in the contract include the interfaces to manage users such as registration, updation and deletion of a user which also update the relevant data members appropriately. If a citizen or an organizational body wants to become a donor, it needs to request to become a donor through rqstDonorMembership method. If approved, they are added to the list of donors. Identity Manager Contract lets users enroll in to the system and maintains identities of registered users along with their roles. A user can register himself as an Indian citizen, an Indian organizational body, a designated Electoral Bond Service Provider (EBSP), an ECI, a designated financial institution which can issue and redeem electoral bonds or a beneficiary political party. The primary data members of the contract are cryptParams which contains the cryptographic public parameters, an identities list which maps a user’s EOA address to an Identity structure containing the non-confidential attributes of the user such as role, a users list which contains the EOA addresses of all registered users and the address of the Electoral Bond Service Provider Contract. Each user can be assigned a role of the citizen, the beneficiary, the financial institution, the organization, the donor, the ECI or the EBSP. The methods in the contract include the interfaces to manage users such as registration, updation and deletion of a user which also update the relevant data members appropriately. If a citizenor an organizational body wants to become a donor, it needs to request to become a donor through rqstDonorMembership method. If approved, they are added to the list of donors.

[0052] Further, the Electoral Bond Service Provider Contract provides a mechanism to let users avail electoral bond services based on their respective roles. The primary data members of the contract include the address of the Identity Manager Contract, IMContract, the unshuffled-encrypted bonds bonds_ush list and the shuffled-encrypted bonds bonds_sh lists. Both bonds_ush and bonds_sh are maintained separately based on the designated denomination amounts. bonds_ush contains the bond identifier, the group elements and the aggregate public key. bonds_sh contains the group elements, the zero-knowledge proof of the correct shuffle and encryption by the financial institution, ZKP^୍౦; the zero-knowledge proof of the validity of the shuffle and encryption process by the EBSP, ZKP^^ୗ^౦; the aggregate public key, the status of the bond, ‘A’ indicating the bond is available for sale, ‘S’ indicating the bond is sold, ‘D’ indicating the bond is donated and ‘C’ indicating the bond is credited. bonds_sh also contains the zero-knowledge proofs CPZKP^୍^and CPZKP^^ୗ^^of the validity of the encryption of each bond done by the financial institution and the EBSP.

[0053] Electoral Bond Service Provider Contract provides services to the user based on the role assigned to the user. A financial institution can generate, issue and redeem the bonds. A donor can purchase and share a bond. A beneficiary party can redeem a bond. ECI personnel and citizens can seek information about the donors, the beneficiaries and the donation made by a specific donor to a beneficiary. At the start of the process, the apex body such as the ECI deploys these two contracts. All users register themselves using the Identity Manager Contract. The users can avail services of the Electoral Bond Service Provider Contract based on their assigned roles. The financial institution creates a set of bonds of designated denominations. Each bond is encoded with a unique identifier referred to as bid. The list is shuffled and encrypted by the financial institution and the EBSP which effectively hides the order of the bonds. For each denomination, the Electoral Bond Service Provider Contract maintains a list of shuffled and unshuffled bonds containing information which helps in finding, the number of bonds issued so far and the bonds which have been redeemed. Double spending of the bonds is prevented by treating bonds as bearer instruments. Only the first redemption of the bond is treated as valid.

[0054] In an embodiment, the system (102) enables registration where all users (106) need to register with the Identity Manager Contract to avail services of the Electoral Bond. The user (106) can be the ECI, the financial institution, the beneficiary party or an Indiancitizen. Based on the category, a role is assigned to the user after appropriate and necessary verification such as KYC. A user is assumed to have a secure wallet that is used to store secure parameters. After successful registration, data members such as users and identities are updated accordingly.

[0055] In an embodiment, the system (102) enables initial setup where the ECI carefully selects the cryptographic parameters such as a finite abelian group G of a largeprime order q with generator g ∈ G in which the Decisional Diffie-Hallman problem is hard.The public parameters are published in cryptParams data member of the Identity Manager Contract. The proposed scheme employs two kinds of keys, one is the aggregate key which is required during the encryption as well as decryption process and the other is the ephemeral key which is required only during the encryption process but not during the decryption process since they get nullified during the decryption process. The ephemeral keys are destroyed immediately after being used in the encryption process. Multiple parties may contribute in the formation of an aggregate key. Each party P୧has an aggregate secret key sk^^୧^and the public key pk^^୧^. Parties P୧and P୨may jointly generate an aggregate public key pk^^୧_୨^using their respective aggregate public keys pk^^୧^and pk^^୨^. An object can be jointly encrypted with pk^^୧_୨^which can only be decrypted when both parties contribute a share of their aggregate private keys. Ephemeral secret and public keys of party P୧are denoted by sk^^୧^and pk^^୧^respectively. The financial institution and the EBSP jointly generate an aggregate public key. The financial institution FI generates a private keysk^^^୍^ ∈ୖ ℤ୯ and corresponding public key pk^^^୍^ ൌ g^୩^^ూ^^. The EBSP generates a privatekey sk^^^^ୗ^^ ∈ୖ ℤ୯ and corresponding public key pk^^^^ୗ^^ ൌ g^୩^^ుా^ౌ^. Both the EBSP and FI store their private keys securely in their respective wallets. The aggregate public keys pk^^୍_^େ୍^^is computed as below equation (4)pk^^^୍_^^ୗ^^ ൌ ^ pk୩^୩ୀ^^^୍^,^^^^ୗ^^^^--- Equation (4)

[0056] In an embodiment, the system (102) is configured to generate a set of n electoral bonds of certain approved denomination amount amt୮. Each bond is uniquelyidentified by a bond identifier bid୧ ∈ ℤା. For each bid୧, the financial institution generatestwo group elements bidG୧^, bidG୧ଶ ∈ G using ElGamal encryption elge൫bid୧, pk^^^୍_^^ୗ^^, 1൯.The financial institution generates the group elements using ElGamal encryption as below equation (5).bid bidG୧^ ൌ g୧ ൌ ^ bidG୧ଶ ൌ bid୧ . pk^^^୍_^^ୗ^^ൠ --- Equation (5)

[0057] An unshuffled electoral bond is represented by a tuple^amt୮, bid୧, bidG୧^, bidG୧ଶ, pk^^^୍_^^ୗ^^^. All bond tuples are published in the ElectoralBond Service Provider Contract as bonds_ush list (refer Figure 3). This functionality is implemented by the method generateB. amt୮, bi Equation (6) æ d୧, ୧^, bidG୧ଶ,pk^^^୍_^^ୗ^^ ø--- Equation (6)

[0058] The bonds are now shuffled and encrypted in turn by the financial institution and the EBSP in a manner that hides the content and the order of the bond identifiers in the sequence. This functionality is implemented by the method shencB. The financial institution randomly selects a permutation matrix P of size n Χ n such that each of its element P୧,୨is either 0 or 1 and the sum of each row and each column is 1. ୬^ P 1, ∈ ^1, 2, … , ^^--- Equation (7) The financial institution generates a shuffled sequence of bonds using the permutation matrix P. ୬ ^, ∀i ∈ ^1, 2, … ,, ∀i ∈ ^1, 2, … ,--- Equation (8) Now, ∀i ൌ 1.. n, the financial institution generates a random numberr୧ ∈ୖ ℤ୯, an ephemeral private key sk^^^୍^^ ൌ r୧, corresponding public key pk^^^୍^^ ൌg^୩ు^ూ^^^and generates homomorphic encryption of the group elements using ElGamal encryption elge ^ ^bidGs^^୍^୧^, bidGs^^୍^^మ^ , pk^^^୍_^^ୗ^^, sk^^^୍^^^ along with a zero-knowledge proof to prove the validity of the encryption using sk^୍^. bidGse^^୍^^୩ు^ూ^^భ ൌ bidGs^^୍^୧^ . g^^bidGse ൌ bidG^୩ు^ూ^^^^^୍^^మ s^^୍^^మ.൫pk^^^୍_^^ୗ^^൯ୠ୧^ୋ^^ ୠ୧^ୋ^^ CPZKP^୍^൬^ూ^^^భୠ୧^ୋ^^ూ^^,^ూ^^^మ , g, pk^^^୍_^^ୗ^^: sk^ ^^భୠ୧^ୋ^^ూ^^ ^^୍^^^మ--- Equation (9)^^, securely. The financialprovides a zero-knowledge proof to prove the integrity of the shuffle verifying that the institution hasn't introduced arbitrary content into the encrypted bid, thus safeguarding against potential decryption attempts in the future (refer Figure 4). This paper uses the notation ZKP^୍౦to denote this proof. Though it is an interactive proof, it can be converted to a non-interactive one using Fiat-Shamir transform. These shuffled encrypted bonds ൫amt୮, bidGse^^୍^^భ, bidGse^^୍^^మ൯ are given to the EBSP.Similar to the financial institution, EBSP generates a permutation matrix P′ and uses it to generate a shuffled sequence of bonds. ୬ ^^ . bidGse^^୍ , ∀i ∈ ^1, 2, … ,. bidGse ౡమ , ∀i ∈ ^1, 2, … ,--- Equation (10) Now, ∀i ൌ 1.. n, the EBSP generates a random number r୧ ∈ୖ ℤ୯, an ephemeral private keysk^^^^ୗ^^^ ൌ r୧, corresponding public key pk^^^^ୗ^^୩ు^ుా^ౌ^^ ൌ g^^and generateshomomorphic encryption of the group elements. using ElGamal encryptionelge ^ ^bidGs^^୍_^^ୗ^^୧^, bidGs^^୍_^^ୗ^^^మ^ , pk^^^୍_^^ୗ^^, sk^^^^ୗ^^^^ along with a zero-knowledge proof to prove the validitybidGse^^୍_^^ୗ^^^୩ు^ుా^ౌ^భ ൌ bidGs^^୍_^^ୗ^^୧^ . g^^bidGse^୩ు^ుా^ౌ^^୍_^^ୗ^^^^^మ ൌ bidGs^^୍_^^ୗ^^^మ.൫pk^^^୍_^^ୗ^^൯ୠ୧^ୋ^^ CPZKP^^ୗ^^൬^ూ^_ుా^ౌ^^భୠ୧^ୋ^^ ୠ୧^ୋ^^ూ^_ుా^ౌ^,^ూ^_ుా^ౌ^^మୠ୧^ୋ^^ూ^_ ^ , g, pk^^^୍_^^ୗ^^: sk^^^^ୗ^^^^^భ ుా^ౌ ^మ--- Equation (11)The EBSP provides azero-knowledge proof ZKP^^ୗ^౦to prove the integrity of the shuffle verifying that the EBSP hasn't introduced arbitrary content into the encrypted bid, thus safeguarding against potential decryption attempts in the future. The following shuffled encrypted list of bonds is published in the Electoral Bond Service Provider Contract as bonds_sh list (refer Fig.2A). amt୮, n--- Equation (12) The contract also maintains the status of the bond indicating whether it is available or sold. Initially, the status of all bonds is marked as “A”, indicating available. If a bond is sold to some donor, its status is later changed to “S”. Once sold, the donor’s receipt is provided to the donor and the group elements and aggregate public key corresponding to the bond are updated. When a donor later donates the bond to a beneficiary, its status is changed to “D”. Once donated, the aggregate public key is updated. The details are explained later in the section.

[0059] In an embodiment, the system (102) enables purchase of electoral bonds. Electoral bonds can only be purchased by an approved donor entity through purchaseB method of the Electoral Bond Service Provider Contract. A donor D୩requests for a purchase of an electoral bond of a certain denomination amt୮. It generates a private key sk^^ୈౡ^∈ୖℤ୯and corresponding public key pk^^ୈౡ^ ൌ g^୩^^ీౡ^. Donor stores its private key securely in its wallet. The aggregate public key pk^^^୍_^^ୗ^_ୈౡ^is computed as below. pk^^^୍_^^ୗ^_ୈౡ^ ൌ pk^^^୍_^^ୗ^_ୈౡ^. pk^^ୈౡ^--- Equation (13) bonds_sh list is looked up for the first available bond of denomination amt୮. Let us assume it is found at the index i. The corresponding group elements are recomputed using sk^^ୈౡ^and a zero-knowledge proof is generated to prove the validity of the computation. bidGjd^^୍_^^ୗ^_ୈౡ^^భ ൌ bidGse^^୍_^^ୗ^^^భbidGjd ^୩^^ీ^^୍_^^ୗ^_ୈౡ^^మ ൌ ൫bidGse^^୍_^^ୗ^^^భ൯ ౡ^ . bidGse^^୍_^^ୗ^^^మୠ୧^ୋ୨^ CPZKP൫ూ^_ుా^ౌ୨ୈౡ൬ pk^^ୈౡ^,_ీౡ൯^మୠ୧^ୋ^^^ూ^_ుా^ౌ^ , g, bidGse^^୍_^^ୗ^^^భ ∶ sk^^ୈౡ^^--- Equation (14)ar୧ an private key sk^^ୈౡ^ ൌ r୧,corresponding public key pk^^ୈౡ^ ൌ g^୩ు^ీౡ^and generates homomorphic encryption of the group elements using ElGamal encryption elge൫൫bidGjd^^୍_^^ୗ^_ୈౡ^^భ, bidGjd^^୍_^^ୗ^_ୈౡ^^మ൯, pk^^^୍_^^ୗ^_ୈౡ^, sk^^ୈౡ^൯ along with azero-knowledge proof to prove the validity of the encryption using sk^^ୈౡ^. bidGed^^୍_^^ୗ^_ୈౡ^^భ ൌ bidGjd^^୍_^^ୗ^_ୈౡ^^భ . g^୩ు^ీౡ^bidGed ౡ^^మ ൌ^୩ు^ీౡ^^^୍_^^ୗ^_ୈ൯bidGed CPZKP^ ^^୍_^^ୗ^_ୈౡ^^భbidGed^^୍_^^ୗ^_ୈౡ^^మୈౡ ^, bidGjd bi, g, pk^^^୍_^^ୗ^_ୈౡ^: sk^^ୈౡ^^^^୍_^^ୗ^_ୈౡ^^భdGjd^^୍_^^ୗ^_ୈౡ^^మ--- Equation (15) The ephemeral private key sk^^ୈౡ^is deleted securely. The bond at the index i is marked as “sold”, the donor’s receipt is provided to the donor, the existing group elements are marked invalid, the recomputed group elements are kept securely by the donor and the public keys along with zero-knowledge proofs are appended in the bonds_sh list which now becomes as below.amt୮, æZKP^୍౦, ZKP^^ୗ^౦,ö. maintains a private extended list of bonds, bonds_sh_ext containing additional details such as donor and the beneficiary. The ECI appends the entry at index i in list bonds_sh_ext with identity D୩of the donor. The communication among entities is secured through TLS and the sender of the message encrypt the data with the EOA public key of the receiver to prevent confidentiality.

[0060] In an embodiment, the system (102) is configured to share bonds with beneficiary party. Before a donor D୩can share bond with a beneficiary political party B୪, it needs to invoke the shareB method of the Electoral Bond Service Provider Contract. The contract verifies the validity of the donor, generates a private key sk^^^^^∈ୖℤ୯andcorresponding public key pk^^^^^ ൌ g^୩^^ా^^. Donor stores the private key securely in its wallet. The aggregate public key pkౡ_^^^is computed aspk^^^୍_^^ୗ^_ୈౡ_^^^ ൌ pk^^^୍_^^ୗ^_ୈౡ^ . pk^^^^^--- Equation (18) The corresponding group elements are recomputed using sk^^^^^and a zero-knowledge proof is generated to prove the validity of the computation.bidGjb^^୍_^^ୗ^_ୈౡ_^^^^భ ൌ bidGed^^୍_^^ୗ^_ୈౡ^^భbidGjb ౡ ^^^^మ ൌ ൫bidG ^୩^^ా^^୍_^^ୗ^_ୈ ^^^^୍_^^ୗ^_ୈ _ ed ౡ^^భ൯ . bidGed^^୍_^^ୗ^^bidGjb CPZKP^^୍_^^ ^୨^^^ pk^^^^^,ୗ^_ୈౡ_^^ ^మbidGed, g, bidGed^^୍_^^ୗ^_ୈ ∶ sk ^^^୍_^^ୗ^_ୈ ౡ^^భ ^^^^^ౡ^^మ--- Equation (19)behalf of beneficiary) generates a random number r୧∈ୖℤ୯, an ephemeralprivate key sk^^^^^ ൌ r୧, corresponding public key pk^^^^^ ൌ g^୩ు^ా^^and generates homomorphic encryption of the group elements using ElGamal encryptionelge൫൫bidGjb^^୍_^^ୗ^_ୈౡ_^^^^భ, bidGjb^^୍_^^ୗ^_ୈౡ_^^^^మ൯, pk^^^୍_^^ୗ^_ୈౡ_^^^ , sk^^^^^൯ along witha zero-knowledge proof to prove the validity of the encryption using sk^^^^^.bidGeb^^୍_^^ୗ^_ୈౡ_^^^^భ ൌ bidGjb^^୍_^^ୗ^_ୈౡ_^^^^భ . g^୩ు^ా^^bidGeb^୩ు^ా_^^^^^^మ ൌౡ_^^bidGeb CPZKP^ ^^୍_^^ୗ^_ୈౡ_^^^^భbidGeb^^୍_^^ୗ^_ୈౡ_^^^^మ^^ ^,, g, pk^^^୍_^^ୗ^_ୈ _^^ : sk^^^^^^ ^^୍_^^ୗ^_ୈ ౡ ^ ^ౡ ^ ^మ--- Equation (20)The ephemeral private key sk^^^^^is deleted securely The bond at the index i is marked ‘D’, i.e., “donated”, the aggregate public key is updated in the bonds_sh list. ECI is also notified of the sharing of bond by donor D୩. The updated group elements and the zero-knowledge proofs are given to the donor and are not stored in the list. amt୮, æZKP^୍౦, ZKP^^ୗ^౦,ö çbidGse^^୍_^^ୗ^^^భ, bidGse^^୍_^^ୗ^^^మ,÷ çbidGjd^^୍_^^ୗ^_ୈ ^ , bidGjd^^୍_^^ୗ^_ୈ ,÷ çౡ ^భ ౡ^^మbidGed^^୍_^^ୗ^_ୈ ^ , bidGed^^୍_^^ୗ^_ ,÷bonds_sh୧ ൌçౡ ^భ ୈౡ^^మ÷ çCPZKP^୍^, CPZKP^^ୗ^^,÷ çCPZKP , CP÷ ç୨ୈౡ ZKP^ ୈౡ,CPZKP , CPZK÷ ç୨^^ P^ ^^÷ pk^^^୍_^^ୗ^_ୈౡ_^^^è"D" ø--- Equation (21) The donor updates its wallet securely as indicated below.amt୮, æ i, bidGedö ÷ ÷ ÷ ÷ ÷ ø --- Equation (22)shares its wallet which includes secret keys sk^^^^^and sk^^ୈే^with the party offline securely. The party stores the received data securely in its wallet.

[0061] In an embodiment, the system (102) the system can be configured to enable redemption of electoral bonds. Electoral bonds can only be redeemed by an approved beneficiary party through the redeemB method of the Electoral Bond Service Provider Contract. The beneficiary provides the following data to the method. amt୮, i, ö ÷ ÷ ÷ ø--- Equation (23) The contract verifies the validity of the group elements and the proof against existing elements at the index i. Once verified, the beneficiary provides the following which includes the zero-knowledge proof to prove the possession of the corresponding secret key and the usage of the same as one of the participating public keys in the aggregate public key.k ൌ ൫bidGeb^୩^^ా^൯^^୧^^^^^ ^୍_^^ୗ^_ୈౡ_^^^^భbidGeb^^୍_^^ୗ^_ୈౡ_^^^^భ, g: sk^^^^^൯--- Equation (24)k ൌ ൫b^୩^^ీౡ^୧^^ୈౡ^ idGeb ൯--- Equation (25)After verification, the contract sends notifications to ECI and financial institution to provide their part. ECI provides the following.k୧^^^^ୗ^^ ൌ ൫bidGeb^୩^^ుా^ౌ^^^୍_^^ୗ^_ୈౡ_^^^^భ൯CPZKP୧^^^୩^^ుా^ౌ^^൫k୧^^^^ୗ^^, pk^^^^ୗ^^, bidGeb^^୍_^^ୗ^_ୈౡ_^^^^భ, g: sk^^^^ୗ^^൯--- Equation (26)The financial institution provides the following.k ൌ ൫bidGeb ൯^୩^^ూ^^୧^^^୍^ ^^୍_^^ୗ^_ୈౡ_^^^^భCPZKP୧^^^୩^^ూ^^^൫k୧^^^୍^^, pk^^^୍^, bidGeb^^୍_^^ୗ^_ୈౡ_^^^^భ, g: sk^^^୍^൯--- Equation (27) The contract obtains bid୧in plaintext by computing the following. bidGeb bid^^୍_^^ୗ^_ୈౡ_^^^^మ୧ൌ ∏୨ୀ୧^^^^ୗ^^,୧^^^୍^, ୧^^ୈౡ^, ୧^^^^^ k୨--- Equation (28)The contract verifies that the bid୧is not already marked ‘C’, i.e. already credited, to prevent double-spending. The contract appends the entry in the list bonds_sh at index i with CPZKP୧^^^୩^^ా^^^, CPZKP୧^^^୩^^ీౡ^^, CPZKP୧^^^୩^^ుా^ౌ^^, and CPZKP୧^^^୩^^ూ^^^. ECI is notified about the redemption request from the beneficiary B୪for the bond bid୧. ECI seeks donor’s identity from the beneficiary, appends the list bonds_sh_ext with beneficiary identity and verifies the information against available information and zero-knowledge proofs. Now, the contract marks the bond at index i in bonds_sh list as ‘C’ and credits the money to the beneficiary’s account.amt୮, æZKP^୍౦, ZKP^^ୗ^౦,ö ÷ , ÷ ÷ , ÷ ÷bonds_sh÷ ୧ൌ÷çୈ ,÷ ౡ ÷ ÷ , ÷ ÷ ÷ ø --- Equation (29)

[0062] In an embodiment, the ECI is the apex governing body of the electoral bond process and has the authority to seek information from the participating entities. ECI receives necessary notifications and information from participating entities at time of bond generation, bond issuance, bond transfer and bond redemption. It securely maintains a private extended list of bonds, bonds_sh_ext containing additional details such as donor and the beneficiary. ECI provides information from this list only the entities which have requisite right to information. Citizens have the right to information and should be provided the details about the donors and the donation received from them by political parties. Citizens request this information through method RTI of the electoral bond service provider contract. The method notifies ECI about this request from a citizen. ECI fetches the information from its securely maintained private bonds_sh_ext list. The information is encrypted with citizen’s EOA public key and is sent back to the citizen.

[0063] In an embodiment, the system (102) maintains the privacy of the donors by not including the identity of the donors in the electoral bonds and unlinkability between the donor and the beneficiary party. At the same time, the system also upholds the right to information by allowing only the users with the necessary right to Information privilege to access this information. Hence, only the citizens and the ECI can access the donor information, and not the financial institution or the non-beneficiary parties.

[0064] In an embodiment, the system (102) maintains the unlinkability between the donor and the beneficiary party. When an electoral bond is issued to a donor, the bondidentifier bid is not known to anybody and is represented by the corresponding group elements. When this bond is shared by the donor with a beneficiary party, the group elements are updated again, though privately this time. Later, when a beneficiary party redeems the bond, it provides updated group elements with necessary proof to prove the validity of the computation. Hence, the financial institution, which is the receiver of the bond, cannot establish a link between the donor and the beneficiary party.

[0065] In an embodiment, the system (102) maintains transparency to the Citizens. Since citizens have the right to information to know the identities of the donors, the beneficiary parties and the amount of donations received by parties from each donor, the proposed system lets citizens obtain this information. Since ECI has the authority to know, the information is authoritatively obtained from the participating entities through smart contracts or else it is deemed as violation of regulatory conduct from the respective entity.

[0066] In an embodiment, the system (102) prevents double-spending. Double- spending of the Electoral Bonds is prevented by finding the bond id of the Bond, marking it as redeemed and deeming only the first redemption valid.

[0067] In an embodiment, the system (102) ensures non-repudiation of electoral bonds. FIG. 2B illustrates an exemplary block diagram representation of electoral bonds. The functionality of the proposed scheme is governed by the smart contract. All participating entities have their own EOA accounts with corresponding private and public keys. All communication messages are secured through TLS, digitally signed by the sender and are verified by the receiver before processing. All the objects, including the electoral bonds, which are transferred and shared among participating entities are digitally signed by the entity claiming the object’s integrity. Hence, no participating entity can repudiate on the message or object it generated.

[0068] FIG. 3 illustrates an exemplary flowchart for a method (300) enabling privacy and transparency in electoral bonds using cryptography and blockchain, in accordance with embodiments of the present disclosure.

[0069] At step (302), bank along with service provider associated with one one or more computing devices (108) generates a shuffled encrypted set of electoral bonds of a predefined denomination using zero-knowledge proof and homomorphic encryption. The one or more processors 114 of the one one or more computing devices 108 collaboratively generate a set of electoral bonds that are shuffled and encrypted. The generation process involves the financial institution and the service provider. Each electoral bond in the generated set is associated with a predefined denomination.

[0070] At step (304), the donor requests for purchase of a set of bonds. In this step, the donor is verified through KYC process and the bonds are sold to the donor. The one or more processors 114 can process a request from one or more donors to purchase a corresponding set of electoral bonds of a predefined denomination. The method includes verifying the one or more donors through a Know Your Customer (KYC) process to ensure compliance with regulatory requirements. Upon successful verification, the purchased electoral bonds are marked as sold and associated with the respective donors, enabling secure and traceable transactions.

[0071] At step (306), the donor shares a subset of purchased bonds with the intended beneficiary. The one or more processors 114 enabling the one or more donors to transfer the purchased electoral bonds to one or more beneficiary entities. At step (308), the beneficiary redeems the bond by submitting it to the to the bank. In this step, the bank verifies the validity of the bond and the beneficiary, retrieves the electoral bond id and marks the bond as credited. The one or more processors 114 facilitate redemption of the transferred electoral bonds by the one or more beneficiary entities through submission to the financial institution, wherein the validity of the transferred electoral bonds and the one or more beneficiary entities is verified, marking the transferred electoral bonds as redeemed upon successful verification.

[0072] As indicated in step (310), all these steps include zero-knowledge proof and homomorphic encryption which enables verifiable computation, unlinkability between the donor and the beneficiary and transparency for the citizens. The one or more processors 114 implements zero-knowledge proof and homomorphic encryption to ensure verifiable computation for each transaction, maintain unlinkability between the one or more donors and one or more beneficiary entities and provide transparency to authorized entities.

[0073] Each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted group elements corresponding to each electoral bond, wherein the homomorphic encryption is a ElGamal encryption. The one or more processors 114 shuffle and re-encrypt the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed. The one or more processors 114 facilitate anonymity of the one or more donors by maintaining mapping between the one or more donors and corresponding bond identifiers anonymous. The one or more processors 114 facilitate the anonymity of the one or more beneficiary entities by maintaining the mapping between the one or more beneficiary entities and the one or more donors anonymous

[0074] The one or more processors 114 facilitate the transparency to the authorized entities by enforcing both the financial institution and the service provider to provide information to a Election Commission of India (ECI) which aggregate information and provide to the authorized entities. The one or more processors configured to initialize the status of each electoral bond as available, modify the status of the corresponding electoral bonds to sold, upon confirmation of the purchase by the one or more donors and modify the status of the corresponding electoral bonds to redeemed, upon confirmation of a valid redemption request by the one or more beneficiary entities.

[0075] The one or more processors 114 prevent double-spending of the set of electoral bonds by marking the corresponding electoral bonds as redeemed upon its first use. The one or more processors 114 configured to prevent the double-spending of the set of electoral bonds by marking the redeemed bonds as spent, verify redemption requests by checking the status of the set of electoral bonds; and ensure that only a first valid redemption request is accepted, rejecting any subsequent redemption attempts.

[0076] FIG. 4 illustrates an exemplary computer system (400) in which or with which embodiments of the present invention can be utilized, in accordance with embodiments of the present disclosure.

[0077] As shown in FIG.4, the computer system (400) can include an external storage device (510), a bus (420), a main memory (430), a read-only memory (440), a mass storage device (450), communication port (460), and a processor (470). A person skilled in the art will appreciate that the computer system may include more than one processor and communication ports. Examples of processor (470) include, but are not limited to, an Intel® Itanium® or Itanium 2 processor(s), or AMD® Opteron® or Athlon MP® processor(s), Motorola® lines of processors, FortiSOC™ system-on-chip processors, or other future processors. Processor (470) may include various modules associated with embodiments of the present invention. Communication port (460) can be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit, or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. Communication port (460) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects. Memory (430) can be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. Read-only memory (440) can be any static storage device(s) e.g., but not limited to, a Programmable Read-Only Memory (PROM) chips for storing static information e.g., start-up or BIOS instructions for the processor (470). Mass storage (450)may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), e.g. those available from Seagate (e.g., the Seagate Barracuda 782 family) or Hitachi (e.g., the Hitachi Deskstar 13K800), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g. an array of disks (e.g., SATA arrays), available from various vendors including Dot Hill Systems Corp., LaCie, Nexsan Technologies, Inc. and Enhance Technology, Inc.

[0078] Bus (420) communicatively couples processor(s) (470) with the other memory, storage, and communication blocks. Bus (420) can be, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), USB, or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects processor (470) to a software system.

[0079] Optionally, operator and administrative interfaces, e.g., a display, keyboard, and a cursor control device, may also be coupled to the bus (420) to support direct operator interaction with a computer system. Other operator and administrative interfaces can be provided through network connections connected through a communication port (460). The external storage device (410) can be any kind of external hard drives, floppy drives, IOMEGA® Zip Drives, Compact Disc – Read-Only Memory (CD-ROM), Compact Disc-Re- Writable (CD-RW), Digital Video Disk-Read Only Memory (DVD-ROM). The components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system limit the scope of the present disclosure.

[0080] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the invention. These and other changes in the preferred embodiments of the invention will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be implemented merely as illustrative of the invention and not as a limitation.

Claims

AMENDED CLAIMS received by the International Bureau on 14 August 2025 (14.08.2025)We Claim:

1. A method (300) for securely managing a set of electoral bonds, the method being implemented by one or more processors (114), the method comprising: generating (302), by the one or more processors (114), the set of electoral bonds that are shuffled and encrypted, the generation is performed collaboratively by a financial institution and a service provider, each electoral bond is associated with a predefined denomination, wherein each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted group elements corresponding to each electoral bond; processing (304) a request from one or more donors to purchase a corresponding set of electoral bonds of the predefined denomination, wherein the one or more donors are verified through a know your customer (KY C) process, and the purchased electoral bonds are marked as sold to respective donors; enabling (306) the one or more donors to transfer the purchased electoral bonds to one or more beneficiary entities; facilitating (308) redemption of the transferred electoral bonds by the one or more beneficiary entities through submission to the financial institution, wherein validity of the transferred electoral bonds and the one or more beneficiary entities is verified, marking the transferred electoral bonds as redeemed upon successful verification; and implementing (310) zero-knowledge proof and homomorphic encryption to ensure verifiable computation for each transaction, maintain unlinkability between the one or more donors and the one or more beneficiary entities and provide transparency to authorized entities; shuffling and re-encrypting, by the one or more processors (114), the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed.

2. The method claimed in claim 1, wherein the homomorphic encryption is a ElGamal encryption.

3. The method claimed in claim 1, wherein the one or more processors (114) facilitate anonymity of the one or more donors by maintaining mapping between the one or more donors and corresponding bond identifiers anonymous.

4. The method claimed in claim 1, wherein the one or more processors (114) facilitate the anonymity of the one or more beneficiary entities by maintaining the mapping between the one or more beneficiary entities and the one or more donors anonymous.

5. The method claimed in claim 1, wherein the one or more processors (114) facilitate the transparency to the authorized entities by enforcing both the financial institution and the service provider to provide information to a Election Commission of India (ECI) which aggregate information and provide to the authorized entities.

6. The method claimed in claim 1, wherein the one or more processors configured to: initialize the status of each electoral bond as available; modify the status of the corresponding electoral bonds to sold, upon confirmation of the purchase by the one or more donors; and modify the status of the corresponding electoral bonds to redeemed, upon confirmation of a valid redemption request by the one or more beneficiary entities.

7. The method claimed in claim 1, wherein the one or more processors (114) prevent double-spending of the set of electoral bonds by marking the corresponding electoral bonds as redeemed upon its first use.

8. The method claimed in claim 6, wherein the one or more processors (114) configured to: prevent the double-spending of the set of electoral bonds by marking the redeemed bonds as spent; verify redemption requests by checking the status of the set of electoral bonds; and ensure that only a first valid redemption request is accepted, rejecting any subsequent redemption attempts.

9. A system (102) for securely managing a set of electoral bonds, the system comprising:one or more processors (114) operatively coupled to a financial institution and a service provider, the one or more processors (114) coupled to a memory (116), the memory storing instructions executable by the one or more processors to: generate the set of electoral bonds that are shuffled and encrypted, the generation is performed collaboratively by the financial institution and the service provider, each electoral bond is associated with a predefined denomination, wherein each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted group elements corresponding to each electoral bond; processes request from one or more donors to purchase a corresponding set of electoral bonds of a predefined denomination, wherein the one or more donors are verified through a know your customer (KYC) process and the purchased electoral bonds are marked as sold to respective donors; enable the one or more donors to transfer the purchased electoral bonds to one or more beneficiary entities; facilitate redemption of the transferred electoral bonds by the one or more beneficiary entities through submission to the financial institution, wherein validity of the transferred electoral bonds and the one or more beneficiary entities is verified, marking the transferred electoral bonds as redeemed upon successful verification; and implement zero-knowledge proof and homomorphic encryption to ensure verifiable computation for each transaction, maintain unlinkability between the one or more donors and the one or more beneficiary entities and provide transparency to authorized entities; and shuffle and re-encrypt the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed.STATEMENT UNDER ARTICLE 19 (1 )AMENDMENTS TO THE CLAIMSAn amended set of claims 1-9 is filed herewith, and a marked-up copy in which the deleted passages are crossed out and added wording is underlined is enclosed with this response, wherein: f) Original Independent Claims 1 and 10 on file is now suitably amended to include the novel, essential and inventive features of the present invention to recite inventiveness. g) Particularly, Original Independent Claim 1 on file is now suitably amended to include the aspects “wherein each electoral bond is identified by a unique bond identifier which is encrypted using the homomorphic encryption to generate encrypted group elements corresponding to each electoral bond” and “shuffling and re-encrypting, by the one or more processors (114), the set of electoral bonds using the zero-knowledge proof, the homomorphic encryption and a permutation matrix, such that content and order of the set of electoral bonds remain concealed” which are supported by original claims 2 and 3 of the as-filed specification respectively. Accordingly, in view of the above merger, few aspects of original claim 2 and entire original claim 3 have been deleted without prejudice. h) Original independent claim 10 has been amended to make it correspond to amended independent claim 1. i) All the claims on file are now amended to re-number, wherever required and as far as applicable, thereof in view of the above amendments. j) All the claims on file have been amended to re-number and / or correct the antecedent bases, wherever required and as far as applicable, thereof in view of the above amendments.No technical amendments or addition of new matter has been done by way of these amendments.

Citation Information

Patent Citations

  • Zero-knowledge proof payments using blockchain

    WO2020123591A1