Anonymous Vote Verification Using Tokens and Audit Recounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic voting systems face issues with voter fatigue and lack of engagement due to the inability to verify the correspondence between the voter's vote and the ballot, leading to distrust and low turnout, which undermines the legitimacy of elected representatives.

Innovation Solution

A method and apparatus for verifying electronic votes by associating each voter with a token generated through authentication, using a signature sequence to generate an audit request, and recounting the tally for comparison with a published tally, while maintaining voter anonymity, employing CDMA access channels for parallel verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If electronic voting is implemented to improve voting efficiency and accessibility, then voter engagement and turnout are improved, but the ability to verify vote correspondence and ensure transparency deteriorates

Engineering Contradiction:
Improvevoting efficiencyVSAvoidvote verification capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism using tokens and signature sequences that mediate between the voter and the ballot. The token acts as a mediator that links the voter to their ballot without revealing identifying information, enabling verification without compromising anonymity. The signature sequence serves as another intermediary that allows verification of vote correspondence through cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical verification methods with electronic and cryptographic mechanisms. Instead of manual verification of vote correspondence, the system uses digital tokens, signature sequences, and processing servers to automatically verify votes. This substitution enables scalable, transparent verification while maintaining voter anonymity through electronic means.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If voter anonymity is maintained to ensure privacy and trust, then voter engagement is improved, but the ability to verify individual vote correspondence deteriorates

Engineering Contradiction:
Improvevoter anonymityVSAvoidvote correspondence information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The token serves as an intermediary that preserves voter anonymity while enabling verification. It links the voter to their ballot without containing identifying information, allowing the system to verify vote correspondence without revealing the voter's identity. The signature sequence acts as another intermediary that enables verification through cryptographic operations without exposing voter information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses cryptographic copying mechanisms where the token and signature sequence create verifiable copies of the vote correspondence relationship. These copies can be processed and verified without revealing the original voter identity, allowing information to be copied and verified while maintaining anonymity through the copying process itself.

Inventive Principle:
Principle #26Copying

3Reliability

If individual vote verification is enabled to improve transparency, then trust in the voting system is improved, but the complexity of the verification process deteriorates

Engineering Contradiction:
Improvesystem transparencyVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into distinct components: token generation during authentication, signature sequence generation by the access manager, audit request generation by the processing server, and tally recounting. This segmentation divides the complex verification process into manageable, sequential steps that can be understood and verified individually, reducing the overall complexity while maintaining transparency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service verification where voters can independently verify their own votes using the provided tokens and signature sequences without requiring manual intervention from election officials. The processing server automatically generates audit requests and recounts tallies, allowing voters to perform verification themselves through a simplified interface that reduces perceived complexity.

Inventive Principle:
Principle #25Self-service

4Productivity

If multiple votes are verified simultaneously to improve efficiency, then processing time is reduced, but the complexity of managing multiple verification requests deteriorates

Engineering Contradiction:
Improveverification throughputVSAvoidparallel verification management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple verification requests into a single processing operation. The processing server receives multiple audit requests and processes them together through a single recounting operation, generating a combined result that can then be distributed back to the requesting voters. This merging approach enables parallel verification of multiple votes while reducing the management complexity by handling them as a unified process.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4128175B1Verifying electronic votes in a voting system
Publication Date: 2026.01.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4128175B1 patent drawingFigure 1
  • EP4128175B1 patent drawingFigure 2
  • EP4128175B1 patent drawingFigure 3a

AI summary

Disclosed is a method for verifying an electronic vote in a voting system, wherein each voter is associated with a respective token generated by an authentication process in the voting system and wherein each token is configured for identifying the respective voter while maintaining an anonymity of the voter in the voting system. The method comprises steps being performed by a device operably connected to the voting system of; obtaining a token associated with a voter for which a vote is to be verified, providing the obtained token to an access manager in the voting system, obtaining a signature sequence generated by the access manager, wherein the signature sequence is generated based on the provided token, generating an audit request based on the obtained signature sequence and the obtained token, wherein the generated audit request comprises a binary sequence of actions to be performed on a ballot associated with the vote to be verified, providing the generated audit request to a processing server in the voting system, and obtaining a recounted tally based on the audit request from the processing server for comparison with a published tally on a bulletin board of the voting system. Corresponding computer program product, apparatus, device, access manager, processing server and voting system are also disclosed.