Electronic Voting System Using Segmented Authentication Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic voting systems over networks face challenges in ensuring the integrity and confidentiality of votes, particularly due to reliance on technical administrators, risks of server malfunctions, and the complexity of implementing secure authentication and encryption methods, which can lead to loss of voter confidence.
Innovation Solution
A method and system that distribute responsibilities among multiple administrative parties, using authentication certificates and single-use passwords to validate electronic ballots anonymously, ensuring that without collusion, the integrity of the ballot is maintained, and fraud is detectable, while reducing the need for complex authentication systems and minimizing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single trusted server is used to verify voter identity and transmit ballots, then authentication is simplified, but the system becomes vulnerable to server malfunctions and loss of voter confidence
Solution Approach 1:
The system divides the trusted server into multiple independent administrative parties, each holding a share of the authentication key. No single party can compromise the system alone, as they would need to collude with others to reconstruct the full key. This segmentation improves reliability while maintaining operational simplicity through automated key distribution.
Solution Approach 2:
The patent introduces a key distribution center as an intermediary that automatically distributes key shares to multiple administrative parties without requiring manual intervention. This mediator enables the system to maintain simplified authentication operations while achieving enhanced reliability through distributed trust.
2Loss of information
If mix-net messages are used to merge or mixing data, then confidentiality is improved, but it becomes difficult to certify the integrity of the data at the end of processing
Solution Approach 1:
The system performs preliminary actions by having the key distribution center distribute authenticated key shares to administrative parties before the mixing process begins. This preliminary key distribution enables subsequent integrity verification of mixed data without compromising confidentiality during the mixing operation.
Solution Approach 2:
The patent implements feedback mechanisms where administrative parties use their key shares to verify the integrity of mixed ballot data. The verification results feed back into the system to confirm that the mixing process maintained both confidentiality and integrity, allowing certification of data quality.
3Reliability
If a trusted third party computer acts as intermediary to verify signatures and transmit ballots, then authentication is strengthened, but the risk of anonymity removal and fraud increases
Solution Approach 1:
The system segments the trusted third party into multiple administrative parties, each holding a portion of the authentication key. This segmentation ensures that no single party can remove anonymity or commit fraud alone, as they would need to collude with other parties to reconstruct the full key, thereby reducing the harmful factors while maintaining strong authentication.
4Reliability
If dated encryption is used to protect against copying intercepted ballots, then security is improved, but the risk of significant aggregation increases
Solution Approach 1:
The patent applies segmentation to the encryption key by distributing it across multiple administrative parties. This segmented key structure protects against copying interception while preventing aggregation attacks, as each party only holds a fragment of the key and cannot independently aggregate information to compromise voter anonymity.
Data Source
AI summary
A method and system for electronic voting over a network, from a terminal (Te) connected to an administrative server (SA) and to a vote-counting server (SCV). An authentication certificate (CA) and a single-use password (UPWe) are calculated and transmitted (A) from the server (SA) to the voter (Eu), an electronic ballot paper (EB) and an anonymous reference (AREu) are transmitted (B) from the terminal (Te) to the server (SCV) and, upon verification (B1) of the anonymous reference, the vote and the paper are validated (B3), the paper is counted, a confirmation of receipt (ACW) and an electoral register document (DVR) are transmitted from the server (SCV) to the terminal (Te). The terminal (Te) signs the register and transmits (C) the signed register (SDVR) to the server (SA) which closes (D1) the vote of the voter (Eu).


