Electronic Voting System Using Segmented Authentication Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic voting systems over networks face challenges in ensuring the integrity and confidentiality of votes, particularly due to reliance on technical administrators, risks of server malfunctions, and the complexity of implementing secure authentication and encryption methods, which can lead to loss of voter confidence.

Innovation Solution

A method and system that distribute responsibilities among multiple administrative parties, using authentication certificates and single-use passwords to validate electronic ballots anonymously, ensuring that without collusion, the integrity of the ballot is maintained, and fraud is detectable, while reducing the need for complex authentication systems and minimizing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single trusted server is used to verify voter identity and transmit ballots, then authentication is simplified, but the system becomes vulnerable to server malfunctions and loss of voter confidence

Engineering Contradiction:
Improveauthentication processVSAvoidvoter confidence
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the trusted server into multiple independent administrative parties, each holding a share of the authentication key. No single party can compromise the system alone, as they would need to collude with others to reconstruct the full key. This segmentation improves reliability while maintaining operational simplicity through automated key distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key distribution center as an intermediary that automatically distributes key shares to multiple administrative parties without requiring manual intervention. This mediator enables the system to maintain simplified authentication operations while achieving enhanced reliability through distributed trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If mix-net messages are used to merge or mixing data, then confidentiality is improved, but it becomes difficult to certify the integrity of the data at the end of processing

Engineering Contradiction:
ImproveconfidentialityVSAvoiddata integrity certification
Core Design Contradiction:
Loss of informationVSManufacturing precision

Solution Approach 1:

The system performs preliminary actions by having the key distribution center distribute authenticated key shares to administrative parties before the mixing process begins. This preliminary key distribution enables subsequent integrity verification of mixed data without compromising confidentiality during the mixing operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where administrative parties use their key shares to verify the integrity of mixed ballot data. The verification results feed back into the system to confirm that the mixing process maintained both confidentiality and integrity, allowing certification of data quality.

Inventive Principle:
Principle #23Feedback

3Reliability

If a trusted third party computer acts as intermediary to verify signatures and transmit ballots, then authentication is strengthened, but the risk of anonymity removal and fraud increases

Engineering Contradiction:
ImproveauthenticationVSAvoidanonymity removal risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the trusted third party into multiple administrative parties, each holding a portion of the authentication key. This segmentation ensures that no single party can remove anonymity or commit fraud alone, as they would need to collude with other parties to reconstruct the full key, thereby reducing the harmful factors while maintaining strong authentication.

Inventive Principle:
Principle #1Segmentation

4Reliability

If dated encryption is used to protect against copying intercepted ballots, then security is improved, but the risk of significant aggregation increases

Engineering Contradiction:
Improveprotection against copyingVSAvoidaggregation risk
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies segmentation to the encryption key by distributing it across multiple administrative parties. This segmented key structure protects against copying interception while preventing aggregation attacks, as each party only holds a fragment of the key and cannot independently aggregate information to compromise voter anonymity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7819319B2Method and system for electronic voting over a high-security network
Publication Date: 2010.10.26 ORANGE SA
  • US7819319B2 patent drawing
  • US7819319B2 patent drawing
  • US7819319B2 patent drawing

AI summary

A method and system for electronic voting over a network, from a terminal (Te) connected to an administrative server (SA) and to a vote-counting server (SCV). An authentication certificate (CA) and a single-use password (UPWe) are calculated and transmitted (A) from the server (SA) to the voter (Eu), an electronic ballot paper (EB) and an anonymous reference (AREu) are transmitted (B) from the terminal (Te) to the server (SCV) and, upon verification (B1) of the anonymous reference, the vote and the paper are validated (B3), the paper is counted, a confirmation of receipt (ACW) and an electoral register document (DVR) are transmitted from the server (SCV) to the terminal (Te). The terminal (Te) signs the register and transmits (C) the signed register (SDVR) to the server (SA) which closes (D1) the vote of the voter (Eu).