Systems and methods for digitally signing an election markup language document
The system digitally signs XML or EML documents using cryptographic hashing and canonicalization to address security risks in digital election systems, ensuring authenticity and integrity through unique electronic signatures and validation processes.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-03-26
AI Technical Summary
Digital election systems face significant security risks such as tampering, cyberattacks, and data breaches, with existing methods failing to ensure the integrity and authenticity of election data through canonicalization and hash value determination.
A system and method for digitally signing XML or EML documents using cryptographic hashing algorithms like RSA and SHA-512, performing canonicalization to standardize the documents, determining hash values, and adding signed hash values with signer identification to ensure authenticity and integrity.
Ensures the authenticity, integrity, and non-repudiation of election-related documents by applying unique electronic signatures and validation processes, enhancing security and trust in digital election systems.
Smart Images

Figure PH2024050020_26032026_PF_FP_ABST
Abstract
Description
[0001] SYSTEMS AND METHODS FOR DIGITALLY SIGNING AN ELECTION MARKUP
[0002] LANGUAGE DOCUMENT
[0003] TECHNICAL FIELD OF THE INVENTION
[0004] The present invention relates to systems and methods for systems and methods for digitally signing one or more extensive markup language (XML) or election markup language (EML) documents using a processing unit or a security component of the said processing unit.
[0005] BACKGROUND OF THE INVENTION
[0006] In the advent of digitalization, election systems adopted wireless communications technologies and cloud services to process and store election data. These technologies offer numerous benefits such as streamlined election processes including the tallying of votes and improved accessibility for voters. However, this shift towards digital election systems has introduced significant risks such the tampering of votes, cyberattacks, unauthorized access, and data breaches, among others. The transition to digital systems has also instigated more complex cyber threats and data intrusions which may include advanced hacking techniques. The traditional methods, however, just rely most often on modest ways of securing the election data. Therefore, there is a need to improve the security and integrity of these systems throughout the entire election process to maintain public trust.
[0007] EP3574482B1 (EP '482) discloses voting systems and methods for collecting votes from multiple voters using multiple identity public keys for identifying a voter. The system uses devices that can generate voting public keys and communicate them securely using cryptography. The devices are also configured to store an identity key pair which includes the public key and a private key. The public key is then signed using the private key. EP '482 also discloses that the cryptography can be performed by using Rivest-Shamis-Adleman encryption algorithm. However, EP '482 fails to disclose the steps of performing a canonicalization step to an election-related markup language document and determining a hash value which further ensures the accuracy and integrity of the election data.
[0008] To address the above-discussed deficiencies of the prior art, the present invention discloses a system and method for utilizing cryptographic tokens in an election system for safeguarding digital assets and electronic transactions. This then ensures the integrity and authenticity of electronic transactions relating to the elections.
[0009] OBJECT OF THE INVENTION
[0010] The object of the present invention is to provide systems and methods for digitally signing one or more extensive markup language (XML) or election markup language (EML) documents using a processing unit or a security component of the said processing unit.
[0011] SUMMARY OF THE INVENTION
[0012] The present invention relates to systems and methods for digitally signing one or more extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents. The systems comprise an at least one processing unit configured to at least: prepare the one or more XML or EML documents; perform a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form; determine a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents; sign the hash value using an at least one private key of one or more signers; create one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and verify the signed XML or EML document by at least extracting the hash value from the signed XML or EML document. The systems further comprise an at least one user interface, connected to the processing unit, for allowing access and configuration to the said processing unit; an at least one data storage device for storing the processed result data by the processing unit; and an at least one communications unit, connected to the processing unit, configured to at least send the processed result data to an at least one third-party device and / or an at least one remote server.
[0013] In the second aspect of this invention, the at least one processing unit of the system is configured to use at least one cryptographic hashing algorithm such as Rivest-Shamir- Adleman (RSA) asymmetric encryption algorithm or a secure hash algorithm (SHA) 512. The present invention relates to methods for digitally signing extensive markup language (XML) or election markup language (EML) documents using an at least one processing unit or an at least one security component, comprising the steps of:
[0014] • preparing the one or more XML or EML documents;
[0015] • performing a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences such as a whitespace or an attribute ordering;
[0016] • determining a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents and wherein the cryptographic hashing algorithm is a Rivest-Shamir-Adleman (RSA) encryption, a secure hash algorithm (SHA) 512, or combinations thereof;
[0017] • signing the hash value using an at least one private key of one or more signers;
[0018] • creating one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and
[0019] • verifying the signed XML or EML document by at least extracting the hash value from the signed XML or EML document.
[0020] BRIEF DESCRIPTION OF THE FIGURES
[0021] The accompanying drawings, which are included to understand the present invention further, are incorporated herein to illustrate the embodiments of the present invention. Along with the description, they also explain the principle of the present invention and are not intended to be limiting. In the drawings:
[0022] FIG. 1 presents a diagram of system components in accordance with a preferred embodiment of the present invention;
[0023] FIG. 2 presents a diagram of system components in accordance with another preferred embodiment of the present invention; and FIG. 3 shows the flow chart of the method for digitally signing extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents relating to the election process.
[0024] DETAILED DESCRIPTION OF THE INVENTION
[0025] The present invention relates to systems and methods for utilizing cryptographic tokens in an election system for safeguarding digital assets and electronic transactions.
[0026] FIG. 1 presents the block diagram of the system for managing an election event, wherein the system 100 communicates with at least one internal or external device such as at least one training kiosk 101, at least one voting machine 102, at least one cloud or remote server 103. This enables the system 100 to exchange data between the said devices preferably the exchange of election data or communication data associated to the election event. The said system 100 may also exchange data between other similar systems 108 for managing the election event or a third-party device 109.
[0027] The system 100 preferably comprises at least one processing unit 104, at least one user interface 105, at least one data storage device 106, and at least one communications unit 107. It is conceivable that the at least one processing unit 104, at least one user interface 105, at least one data storage device 106, and at least one communications unit 107 are interconnected such that a data exchange exists between them. The at least one processing unit 104 processes the data received by the system 100 which can be through the at least one user interface 105 as inputted by one or more users or received via the at least one communications unit 107. The processed data can be training data or profile associated to at least one election officer relating to the training and / or certification of the said election officer via the processing unit 104 or a dedicated component of the processing unit 104. The processed data can also be data exchanged with at least one training kiosk 101 as preprocessed by at least one kiosk processing unit and communicated via the training kiosk's 101 kiosk communications unit. In another preferred embodiment, the processed data relate to the election data communicated by at least one voting machine 102.
[0028] In a preferred embodiment, the system 100 comprises at least one processing unit 104 which can be any microcontroller, microprocessor, or any hardware device capable of processing data, issuing instructions, or executing calculations associated to the election event. The processing unit 104 is configured to perform at least one functionality such as:
[0029] • allow an at least one voter to register for the election event;
[0030] • deploy an at least one election officer;
[0031] • manage an at least one election activity and an at least one election subprocess associated to the election event;
[0032] • implement at least one security protocol for the election event;
[0033] • collate result data from an at least one voting machine 102;
[0034] • process the collated result data; and
[0035] • present the collated and processed result data via an at least one digital means.
[0036] The at least one processing unit 104 preferably performs advanced processing means such as intelligent systems, predictive algorithm, artificial neural networks, fuzzy logic, genetic algorithm, machine learning, deep learning, or combinations thereof. This enables the system 100 to perform its operations with more time efficiency and accuracy.
[0037] In a preferred embodiment, the system 100 comprises at least one user interface 105 which is provided to at least one election officer or an authorized user. This can then display the data associated to the election event or means for controlling the system 100 such as accessing the system configuration, security settings, any means for managing the said system 100, or an overview of the management of the election event. Preferably, the user interface 105 is one or more input devices, input / output devices or display / input devices which may include simple analog buttons, a system of switches, digital displays, liquid crystal displays (LCD), light emitting diode (LED) displays, multi-point touch input screens, or combinations thereof. It is conceivable that the user interface 105 provides an at least one means for user interaction with the system 100.
[0038] In a preferred embodiment, the system 100 comprises at least one data storage device 106 for storing election data, associated to the election event, after being processed by the processing unit 104. The at least one data storage device 106 stores the processed result data by the processing unit 104. Preferably, the said election data are stored before sending the said data to other devices. This aims to lessen the risk of data loss by providing a backup storage within the system 100 which can also be used in data aggregation. It is preferred that the at least one data storage device 106 is a non-transitory machine-readable medium storing computer-readable instructions or memory devices that can be any medium or mechanism for storing or transmitting information in a form readable by a machine or computer. The at least one data storage device 106 or the memory device can have a primary memory device and / or a secondary memory device as a backup storage device. The at least one data storage device 106 can be a read only memory (ROM), random access memory (RAM), magnetic disk storage media, hard disk storage, optical storage media, flash memory devices, universal serial bus (USB) drive, secure digital (SD) card, memory chip, or a combination thereof.
[0039] In a preferred embodiment, the system 100 comprises at least one communications unit 107 to enable the exchange of data between the system 100 and at least one internal or external device such as, but is not limited to, at least one training kiosk 101, at least one voting machine 102, at least one cloud or remote server 103, one or more similar systems for managing the election event 108, and / or one or more third-party devices 109. The exchange of information can be the transfer of sensitive election data such as the polling results, the user or voter's data including personal data, and / or election event data, for example. The at least one communications unit 107 can be any transmitter, receiver, or transceiver used for long range (LoRa) modulation, radio frequency (RF), wireless fidelity (Wi-Fi), Bluetooth, infrared, near field communication (NFC), visible light communication, microwave communication, satellite communication, Li-Fi, WiMax, ZigBee, cellular communication, code division multiple access (CDMA), 2G, global system for mobiles (GSM), 3G, 4G, long term evolution (LTE), long term evolution advanced (LTE-advanced), 5G, 5.5G, 6G, 6.5G, 7G, any other wireless communications protocol, or a combination thereof. The use of the said communications protocols establishes versatility and future proofing of the system 100 by allowing the selection of the most suitable communications unit for a certain physical environment or the location of the voting precinct. For example, if the voting precinct is located in a remote rural area, then the communications unit 107 can be configured to use long range (LoRa) modulation, radio frequency (RF), microwave communication, satellite communication, or combinations thereof. This further enables the assurance of data transmission while also incorporating means for data security.
[0040] In another preferred embodiment, the system 100 communicates with at least one training kiosk 101 via the at least one communications unit 107 via wired or wireless means. The at least one training kiosk 101 is configured to provide one or more modules for recruitment, training, and deployment of at least one election officer. The training kiosk 101 operates with the processing unit 104 to provide comprehensive training, simulations, and assessments in a digital environment.
[0041] In yet another preferred embodiment, the system 100 communicates with at least one voting machine 102 via the at least one communications unit 107. The at least one voting machine 102 is preferably a device for computing, collating, verifying authenticity, or performing an at least one process on the machine-readable data in the election ballots via the scanning of the said ballots, counting the votes for a particular candidate, and collating election data, for example. The said machine-readable data are preferably election data associated to the election event. The voting machine 102 can also be an advanced counting machine that ensures the security, accuracy, and transparency of the election event of the election process. Preferably, the at least one voting machine 102 is reconfigurable and offers easy customization by an authorized election officer to accommodate a wide range of election types and election related activities. This ensures interoperability with the system 100 as well as the other devices used for the election event. It is preferred that the voting machine 102 comprises parts allowing modularity and ensuring the ease to upgrade the voting machine's 102 parts accommodating new technologies. The said features ensure that the voting machine 102 remains up to date with the latest advancements, providing long-term sustainability and reliability in election management. For example, the voting machine 102 utilizes user authentication and digital signing using hardware cryptography preferably through public key infrastructure (PKI) wherein the PKI is a system of processes, technologies, and policies that allows the encryption and signing of data. Moreover, the use of PKI allows the voting machine 102 to issue digital certificates that authenticate the identity of the voters, ballots, services relating to the election event, other voting machines and / or the voting machine 102 itself. The said digital certificates creates a secure connection between the system 100 and / or voting machine 102 with the cloud / remote server 103. In another possible embodiment, the voting machine 102 comprises one or more means for authentication such as biometric authentication to check if the voter is registered to cast votes on a specific voting machine 102. In another preferred embodiment, the voting machine 102 utilizes multilingual support which aims to provide translation of machine instructions to different languages or dialects, as well as handicapped persons or persons with disability (PWD)-friendly instructions depending on the voting machine's 102 location or user preferences such as the use of audible instructions or the Braille system. This feature ensures that the voting machine 102 is operable by the election officer and / or the voter regardless of any disability while also dismissing language barriers. In yet another preferred embodiment, the voting machine 102 comprises one or more tracking device to monitor or determine the voting machine's geographical location and one or more internal or external condition using at least one sensor, wherein the internal or external condition relates to, but is not limited to, ambient temperature, internal temperature, humidity, vibration, orientation, or combinations thereof. In another embodiment, the voting machine 102 can be located remotely to facilitate absentee voting, for example. In this case, the voting machine 102 determines and logs its geographical location and transmits the data to the system 100 or a central server for security and monitoring. This feature is to facilitate the election to voters living abroad or those who are unable to attend the official voting location in the determined time.
[0042] According to an embodiment of the invention, the election data comprises one or more information relating to the election process such as, but not limited to, at least one election title, at least one precinct name associated to at least one geographical location where the election process is conducted, one or more election candidate information or the candidates' names for a particular position, or at least one political party name, for example. It is conceivable that the said election data are machine-readable data or intelligible codes that are configured to be accessed and / or processed by at least one system 100, at least one training kiosk 101, at least one voting machine 102, at least one cloud or remote server 103, and / or at least one third-party device 109 in a secured manner via at least one wired or wireless means.
[0043] In still another preferred embodiment, the system 100 communicates with at least one cloud or remote server 103 via the at least one communications unit 107. The at least one cloud or remote server 103 is a remotely available complex processing unit that can utilize one or more servers, databases, computers, microcontrollers, microprocessors, or any hardware device capable of processing data, issuing instructions, or executing calculations. It is conceivable that the cloud or remote server 103 can perform parallel computing if complex data, analysis, or decision is required. The cloud or remote server 103 can be accessed via any communications protocol such as but is not limited to long range (LoRa) modulation, radio frequency (RF), wireless fidelity (Wi-Fi), fiber optics, wired communications media, Bluetooth, infrared, near field communication (NFC), visible light communication, microwave communication, satellite communication, Li-Fi, WiMax, ZigBee, cellular communication, code division multiple access (CDMA), 2G, global system for mobiles (GSM), 3G, 4G, long term evolution (LTE), long term evolution advanced (LTE-advanced), 5G, 5.5G, 6G, 6.5G, 7G, or a combination of thereof.
[0044] In another preferred embodiment, the system 100 communicates with one or more other systems 108 for managing another election process, any election subprocess, or any election related process via the at least one communications unit 107. The one or more other systems 108 can be connected in a same local area network (LAN), a wireless local area network (WLAN), a cellular network, a metropolitan area network (MAN), or a wide area network (WAN). It is conceivable that the one or more systems 108 are located in a different geographic location such as one or more precincts and / or one or more voting areas to perform the tasks associated to the election process.
[0045] In another preferred embodiment, the system 100 communicates with one or more third- party devices 109 via the at least one communications unit 107. The one or more third-party devices 109 can be an authorized network device capable of receiving election data such as the election results which can be a smartphone or computer connected either to an internal or external network.
[0046] FIG. 2 presents a diagram of system components in accordance with a preferred embodiment of the present invention. The processing unit 104 of the system 100 is expanded to include at least one component that is dedicated to process at least one functionality. This may further enable faster processing times, increased accuracy, and / or better system management exhibited by device isolation in case an error in the system occurs. The said advantages are achieved by having a dedicated component that is focused on a certain task wherein its processing power or computational capability is fully optimized. Preferably, the processing unit 104 comprises at least one component such as, but is not limited to, at least one registration component 203, at least one training and certification component 204, at least one election management and configuration component 205, at least one ballot designer component 206, at least one security component 207, at least one result aggregation component 208, at least one online voting component 209, at least one transparency portal component 210, and / or at least one analytics component 211.
[0047] In a preferred embodiment, the processing unit 104 comprises at least one registration component 203. The at least one registration component 203 is preferably configured to allow an at least one voter to register for the election event. The registration component 203 preferably manages the registration of eligible voters while ensuring the accuracy and the integrity of voter rolls, eligible voters list, voter registration data, and / or voter database. Preferably, the registration component 203 comprises at least one means to verify the identity of at least one voter as well as to ensure that the voters meet the eligibility criteria, and / or at least one voting requirement.
[0048] In a preferred embodiment, the processing unit 104 comprises at least one training and certification component 204. The at least one training and certification component 204 is preferably configured to manage the deployment of an at least one election officer.
[0049] In a preferred embodiment, the processing unit 104 comprises at least one election management and configuration component 205. The at least one election management and configuration component 205 is preferably configured to manage an at least one election activity and an at least one election subprocess associated to the election event.
[0050] In a preferred embodiment, the processing unit 104 comprises at least one ballot designer component 206. The at least one ballot designer component 206 is preferably a digital platform, app, or software that is used for designing a ballot for the election process.
[0051] In a preferred embodiment, the processing unit 104 comprises at least one security component 207. The at least one security component 207 is preferably configured to ensure the security of the election event. It is preferred that the at least one security component 207 is configured to safeguard digital assets and ensure the integrity and authenticity of the election related transactions such as the processing and transmission of the election data. The supplementary security component 207 is a unit, device, or a processing unit that is configured to perform or implement at least one security protocol for the election event.The security component 207 can be an authentication, authorization, and accounting (AAA) device, at least one security gateway, at least one firewall configured to act as the primary safeguard security tool such as, but is not limited to, a packet filtering firewall, stateful packetfiltering firewall, proxy firewall, web application firewall, or at least one intrusion detection system (IDS), host-based IDS, network-based IDS, or at least one intrusion prevention system (IPS), or a combination of IDS and IPS. In some embodiments, the security component 207 can also be a unified threat management (UTM) device that consolidates various security functions and features such as network firewall, intrusion detection and prevention, gateway anti-virus, proxy firewall functionality, deep packet analysis, web content filtering and proxy, data loss prevention (DLP), security event and information management (SIEM), virtual private network (VPN) capabilities , endpoint protection, endpoint detection and response (EDR), network detection and response (NDR), extended detection and response (XDR), or combinations thereof.
[0052] In another preferred embodiment, the processing unit 104 comprises at least one security component 207, wherein the security component 207 is configured to utilize cryptographic tokens in an election system for safeguarding digital assets and electronic transactions. Preferably, the processing unit 104 is at least one application specific integrated circuit (ASIC). More preferably, the security component 207 is a dedicated processing device such as at least one application specific integrated circuit (ASIC) for a dedicated implementation of one or more tasks, processes, one or more set of instructions. Through the delegation of the tasks to the security component 207, the performance and energy efficiency of the processing unit 104 is increased. This may also reduce the costs associated with the implementation of the system's 100 functionalities. This is especially beneficial for election processes when a large amount of data are received, analyzed and processed. In some embodiments, the at least one processing unit 104 and / or the security component 207 can be any microcontroller, microprocessor, field programmable gate arrays (FPGA), or any hardware device capable of processing data, issuing instructions, or executing calculations associated to the election event.
[0053] The at least one processing unit 104 and / or the at least one security component 207 is configured to perform at least one functionality relating to the method for digitally signing extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents. According to the embodiments of this invention, the XML or the extensible markup language exhibits versatility and is utilized for structuring and encoding documents. The XML documents are both machine and human readable which makes them adaptable for various applications. This means that a user or an election officer can define at least one custom tag and attributes which organizes the XML documents' structured data in a hierarchical format.
[0054] In another embodiment, the EML or the election markup language is a specialized markup language that is used to represent election-related data relating to the elections, voting processes, and electoral systems. Preferably, the EML follows a hierarchical structure which employs tags to enclose data. EML also allows the customization of tags and attributes to adhere with the unique requirements of election-related information.
[0055] In relation to the digital signing of the XML and / or EML, the functionalities that the at least one processing unit 104 and / or the at least one security component 207 can perform comprises the steps of:
[0056] • preparing the one or more XML or EML documents;
[0057] • determining a canonicalized XML or EML documents by performing a canonicalization step to the prepared XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences such as a whitespace or an incorrect attribute ordering;
[0058] • determining a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents;
[0059] • signing the hash value using an at least one private key of one or more signers;
[0060] • creating one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and
[0061] • verifying the signed XML or EML document by at least extracting the hash value from the signed XML or EML document.
[0062] In another preferred embodiment, the at least one processing unit 104 and / or the at least one security component 207 are configured to perform the process of digital signing for ensuring the authenticity and integrity of the digital documents relating to the election process. The said process applies a unique electronic signature to each of the digital documents. The process further includes a validation process to verify that the said digital documents are unaltered and came from a trusted source. To implement digital signing and validation, the system 100 uses one or more libraries to develop reprogrammable processes, incorporating at least one soft token and / or at least one hard token, wherein both tokens are available in PKI token and smartcard formats. Preferably, during the digital signing process, the at least one processing unit 104 and / or the at least one security component 207 uses one or more libraries such as, but is not limited to, Ixml, endesive, OpenSSL, cryptography, Python- pkcsll, or combinations thereof. The said libraries can be used for both XML and PDF documents that needs digital signing. However, it is preferred that the OpenSSL and cryptography libraries are used for machines while Python-pkcsll and endesive are for digital signing of one or more tokens or cards.
[0063] In another preferred embodiment, the at least one processing unit 104 and / or the at least one security component 207 are configured to perform the validation of digital documents either independently or through the use of validation algorithms such as xmlsec for XML documents and Adobe reader for PDF documents.
[0064] In some embodiments, the at least one processing unit 104 and / or the at least one security component 207 are configured to perform portable document format (PDF) signing and validation. The said processes are used to ensure the authenticity, integrity, and validity of PDF documents, particularly in electronic or digital transactions relating to the election process. The process of PDF signing comprises the step of applying at least one digital signature to a PDF document using at least one digital certificate. The digital signature is conceivable as a cryptographic mechanism that binds the signer or the authorized user's identity to at least one election related document. This ensures that the document has not been altered since it was signed, and that the signer or the authorized user cannot repudiate their signature. The said process of PDF signing helps verify the authenticity of the document and the signer's identity.
[0065] In some embodiments, the at least one processing unit 104 and / or the at least one security component 207 are configured to perform portable document format (PDF) validation. This validation process verifies the digital signature on at least one PDF document to ensure the document's integrity and authenticity. The process comprises a step of checking the signature against the signer's digital certificate to confirm that the document is valid and has not been tampered with. The validation also verifies that the document has not been altered since the document was signed.
[0066] In a preferred embodiment, the processing unit 104 comprises at least one result aggregation component 208. The at least one result aggregation component 208 is preferably configured to collate result data from an at least one voting machine 102. In a preferred embodiment, the processing unit 104 comprises at least one online voting component 209. The at least one online voting component 209 is, preferably, a digital platform configured to perform means for implementing security measures or maintaining the accuracy and transparency of the election event or election process. The online voting component 209 comprises a modular architecture that allows for easy customization and adaption to accommodate different election events or election scenarios.
[0067] In a preferred embodiment, the processing unit 104 comprises at least one transparency portal component 210. The at least one transparency portal component 210 is preferably configured to allow at least one voter or any person to have access to the result data and / or election data or the election results via at least one electronic means such as, but is not limited to, an online application or website accessible by a smartphone, a computer, a third-party device, or combinations thereof. It is conceivable that the transparency portal component 210 provides a trusted and reliable source of information about the status of the election results.
[0068] In a preferred embodiment, the processing unit 104 comprises at least one analytics component 211. The at least one analytics component 211 is preferably configured to process the collated result data from the result aggregation component 208. In some embodiments, the at least one analytics component 211 preferably performs advanced processing means such as intelligent systems, predictive algorithm, artificial neural networks, fuzzy logic, genetic algorithm, machine learning, deep learning, or combinations thereof. The analytics component 211 provides an analysis tool for post-election statistics and helps the election officer to easily analyze election data or result data, log files, search, and filter any data to help optimize the system's 100 performance, identify security threats, and streamline the troubleshooting of the election event or process, election activities, or election subprocesses.
[0069] In another preferred embodiment, the system 100 communicates with at least one training kiosk 101 via wired or wireless means provided by the at least one communications unit 107. The at least one training kiosk 101 comprises at least one kiosk interface 200, at least one kiosk communications unit 201, and at least one kiosk processing unit 202.
[0070] The at least one training kiosk 101 comprises at least one kiosk interface 200, wherein the at least one kiosk interface 200 can be one or more input devices, input / output devices or display / input devices which may include simple analog buttons, a system of switches, digital displays, liquid crystal displays (LCD), light emitting diode (LED) displays, multi-point touch input screens, or combinations thereof.
[0071] The at least one training kiosk 101 comprises at least one kiosk communications unit 201, wherein the at least one kiosk communications unit 201 enables the transfer of data via wired or wireless means from the training kiosk 101 to the system 100, to another system used for election 108, or to a third-party device 109. The at least one kiosk communications unit 201 can be any transmitter, receiver, or transceiver used for long range (LoRa) modulation, radio frequency (RF), wireless fidelity (Wi-Fi), Bluetooth, infrared, near field communication (NFC), visible light communication, microwave communication, satellite communication, Li-Fi, WiMax, ZigBee, cellular communication, code division multiple access (CDMA), 2G, global system for mobiles (GSM), 3G, 4G, long term evolution (LTE), long term evolution advanced (LTE-advanced), 5G, 5.5G, 6G, 6.5G, 7G, any other wireless communications protocol, or a combination thereof.
[0072] The at least one training kiosk 101 comprises at least one kiosk processing unit 202, wherein the at least one kiosk processing unit 202 is a dedicated processing unit that is integrated or embedded in the training kiosk 101. This enables the isolation of the processing function from the system 100. Moreover, the at least one training kiosk 101 can be a device that is remotely located physically or geographically and is connected in a different network from the system 100. The connection between the training kiosk 101 and the system 100 is then enabled by the at least one kiosk communications unit 201. Preferably, the at least one kiosk processing unit 202 can be any microcontroller, microprocessor, or any hardware device capable of processing data, issuing instructions, or executing calculations associated to the election process preferably related to the management of the training and deployment of one or more election officer for the election process.
[0073] In a preferred embodiment, the at least one kiosk processing unit 202 preferably performs advanced processing means such as intelligent systems, predictive algorithm, artificial neural networks, fuzzy logic, genetic algorithm, machine learning, deep learning, or combinations thereof. This enables the training kiosk 101 to perform its operations with more time efficiency and accuracy.
[0074] The at least one training kiosk 101 further comprises at least one kiosk data storage device for storing any data associated to the election or training process. It is preferred that the at least one kiosk data storage device is a non-transitory machine-readable medium storing computer-readable instructions or memory devices that can be any medium or mechanism for storing or transmitting information in a form readable by a machine or computer. The at least one kiosk data storage device or the memory device can have a primary memory device and / or a secondary memory device as a backup storage device. The at least one kiosk data storage device can be a read only memory (ROM), random access memory (RAM), magnetic disk storage media, hard disk storage, optical storage media, flash memory devices, universal serial bus (USB) drive, secure digital (SD) card, memory chip, or a combination thereof.
[0075] FIG. 3 shows the flow chart of the method for digitally signing extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents relating to the election process, wherein the said method is performed by at least one processing unit and / or a at least one security component of the said processing unit. The method comprises the steps of:
[0076] • preparing the one or more XML or EML documents (step 300);
[0077] • performing a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences such as a whitespace or an attribute ordering (step 301); • determining a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents (step 302);
[0078] • signing the hash value using an at least one private key of one or more signers (step 303);
[0079] • creating one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents (step 304); and
[0080] • verifying the signed XML or EML document by at least extracting the hash value from the signed XML or EML document (step 305).
[0081] In step 300, one or more XML or EML documents relating to the election process are prepared. The XML and / or the EML documents comprises data preferably election data, instructions, or any other content in XML / EML format.
[0082] In step 301, a canonicalization step is performed to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are transformed into a standard form, removing one or more irrelevant differences such as a whitespace or an attribute ordering which could affect the digital signing process.
[0083] In step 302, one or more hash values, which may also be referred to as a digest, of the determined canonicalized XML or EML documents are determined or calculated using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents. The cryptographic hashing algorithm is preferably a Rivest-Shamir-Adleman (RSA) asymmetric encryption algorithm or more preferably a secure hash algorithm (SHA) 512.
[0084] In another preferred embodiment, the cryptographic hashing algorithm is a Rivest-Shamir- Adleman (RSA) encryption algorithm. By using RSA, at least one private key and at least one public key is used for the digital signing process. The private key is kept as a secret and is known only by the user or the election officer or the creator of the key pair, while the public key can be available to any other user. The use of RSA provides additional security to the election process by not requiring key sharing. RSA is also faster compared to other encryption methods. Moreover, RSA preserves data integrity wherein the election data cannot be changed while being communicated between different users or between the election management system and one or more voting machines.
[0085] In another preferred embodiment, the cryptographic hashing algorithm is preferably a secure hash algorithm (SHA) 512. SHA 512 is used to convert text of any length into a fixed-size string wherein each output produces a SHA-512 length of 512 bits (64 bytes). The use of SHA 512 provides a vast number of possible output combinations which provides the system with robustness and improved resistance to various cryptographic attacks such as brute force attacks and collision vulnerabilities.
[0086] In step 303, one or more hash values or the digest are signed using an at least one private key of one or more signers, wherein the private key is kept secret and is known only to the signer or at least one authorized election officer.
[0087] In step 304, one or more signed XML or EML documents are created by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents. This step may also be referred to as a signature generation step since the signature along with the information about the signing algorithm and the signer's identity is added to the XML and / or the EML document creating one or more signed XML and / or EML documents.
[0088] In step 305, a verification step is performed. To verify the signature, at least one recipient of the signed XML and / or the EML document needs access to the signer's public key. The hash value (or digest) and the signature are extracted from the signed XML document. The hash value (or digest) is recalculated using the same algorithm and is compared to the original hash value or digest. If the recalculated hash value (or digest) is similar to the original hash value (or digest), then the signature is valid. This also means that the verification is accepted ensuring that the election data are secured. In the event of a mismatch between the recalculated hash value (or digest) and the original hash value (or digest), a notification or alert is provided to at least one authorized user or election officer, preferably in real-time. In the preferred embodiment, the process of digital signing for ensuring the authenticity and integrity of the digital documents relating to the election process. The said process applies a unique electronic signature to each of the digital documents. The process further includes a validation process to verify that the said digital documents are unaltered and came from a trusted source. To implement digital signing and validation, the system 100 uses one or more libraries to develop reprogrammable processes, incorporating at least one soft token and / or at least one hard token, wherein both tokens are available in PKI token and smartcard formats.
[0089] In another preferred embodiment, the digital signing of at least one XML and / or EML document comprises the steps of adding at least one signature template; generating at least one digest value; generating at least one signature value; and extracting at least one certificate.
[0090] The method for digital signing a portable document format (PDF) using the at least one processing unit and / or the at least one security component comprises the steps of: opening an unsigned PDF file; extracting a private key and certificate from a pl2 file (OpenSSL); signing the PDF file; and exporting the signed PDF file.
[0091] The method for validating a signed portable document format (PDF) using the at least one processing unit and / or the at least one security component comprises the steps of: opening a signed PDF file; verifying the signed PDF file preferably using endesive; and printing the results.
[0092] It is contemplated for embodiments described herein to extend to individual elements and concepts described herein, independently of other concepts, ideas or system, as well as for embodiments to include combinations of elements recited anywhere in this application. It is to be understood that the invention is not limited to the embodiments described in detail herein with reference to the accompanying drawings. As such, many variations and modifications will be apparent to practitioners skilled in this art. Illustrative embodiments such as those depicted refer to a preferred form but are not limited to its constraints and are subject to modification and alternative forms. Accordingly, it is intended that the scope of the invention be defined by the following claims and their equivalents. Moreover, it is contemplated that a feature described either individually or as part of an embodiment may be combined with other individually described features, or parts of other embodiments, even if the other features and embodiments make no mention of the said feature. Hence, the absence of describing combinations should not preclude the inventor from claiming rights to such combinations.
Claims
CLAIMS1. A system for digitally signing one or more extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents, comprising: an at least one processing unit (104) configured to at least: prepare the one or more XML or EML documents; perform a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences; determine a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents; sign the hash value using an at least one private key of one or more signers; create one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and verify the signed XML or EML document by at least extracting the hash value from the signed XML or EML document. an at least one user interface (105), connected to the processing unit (104), for allowing access and configuration to the said processing unit (104); an at least one data storage device (106) for storing the processed result data by the processing unit (104); and an at least one communications unit (107), connected to the processing unit (104), configured to at least send the processed result data to an at least one third-party device (109) and / or an at least one remote server (103).
2. The system of claim 1, wherein the cryptographic hashing algorithm is preferably a Rivest- Shamir-Adleman (RSA) asymmetric encryption algorithm or more preferably a secure hash algorithm (SHA) 512.
3. The system of claim 1, wherein the processing unit comprises an at least one security component (207) or an at least one application specific integrated circuit (ASIC) configured to perform an at least one function of the processing unit (104) such as: preparing the one or more XML or EML documents; performing a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences; determining a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents; signing the hash value using an at least one private key of one or more signers; creating one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and verifying the signed XML or EML document by at least extracting the hash value from the signed XML or EML document.
4. A method for digitally signing extensive markup language (XML) or election markup language (EML) documents to ensure authenticity, integrity, and non-repudiation of the said documents using an at least one processing unit and / or a , comprising the steps of: preparing the one or more XML or EML documents; performing a canonicalization step to the prepared XML or EML documents to determine one or more canonicalized XML or EML documents, wherein the canonicalization step ensures that the XML or EML documents are in a standard form by removing one or more irrelevant differences such as a whitespace or an incorrect attribute ordering; determining a hash value of the determined canonicalized XML or EML documents using one or more cryptographic hashing algorithm, wherein the hash value represents one or more content of the XML or EML documents; signing the hash value using an at least one private key of one or more signers;creating one or more signed XML or EML documents by adding the signed hash value, one or more signing algorithm, and the signer's identification to the XML or EML documents; and verifying the signed XML or EML document by at least extracting the hash value from the signed XML or EML document.
5. The method of claim 4, wherein the cryptographic hashing algorithm is a Rivest-Shamir- Adleman (RSA) encryption algorithm.
6. The method of claim 4, wherein the cryptographic hashing algorithm is a secure hash algorithm (SHA) 512.
Citation Information
Patent Citations
Digital signature system, digital signature method, digital signature mediation method, digital signature mediation system, information terminal and storage medium
US20020049906A1
Digital-signed digital document exchange supporting method and information processor
US20060168650A1
Computer-implemented methods, systems and computer program products for generating and verifying signatures
US20100082993A1
Optimization of Signing SOAP Body Element
US20100268952A1
Method and device for creating digital signature
US20110185180A1