Skip to main content
QUICK REVIEW

[论文解读] A short introduction to secrecy and verifiability for elections

Elizabeth A. Quaglia, Ben Smyth|arXiv (Cornell University)|Feb 10, 2017
Internet Traffic Analysis and Secure E-voting被引用 5
一句话总结

本文提出了电子选举中投票保密性和可验证性的形式化安全定义,展示了如何在Helios等方案中对这些特性进行数学证明。结果表明,结合加密与零知识证明可同时实现隐私保护与端到端可验证性,确保选票保密的同时允许独立验证计票结果的正确性。

ABSTRACT

We explore the fundamental properties that are necessary to ensure that election schemes behave as expected. The exploration reveals how our understanding of those expectations has evolved, culminating in the emergence of formal definitions of properties necessary to fulfil expectations. We provide insights into definitions of secrecy and verifiability, allowing us to learn and appreciate the underlying intuition and technical details of these notions. Equipped with definitions, we can build election schemes that can be proven to behave as expected. And, as an illustrative example, we review a variant of the Helios election system that was built and proven secure, in this way. Furthermore, the definitions can be used to analyse existing election schemes, and vulnerabilities have been uncovered. Indeed, we describe a series of vulnerabilities that were discovered during the analysis of the original Helios system, which advanced our understanding of system behaviour and prompted the design of the aforementioned variant. Thus, this article contributes to the science of security by sharing valuable insights into elections, and demonstrating the value that formal definitions and analysis have in building schemes guaranteed to behave as expected.

研究动机与目标

  • 为解决现有选举方案缺乏科学基础的问题,这些方案通常依赖于临时设计,易受胁迫和操纵影响。
  • 建立形式化、可机器检查的投票保密性与可验证性安全定义,确保其可被正确证明。
  • 证明安全选举方案(如Helios)可通过形式化验证与实现正确性得到增强。
  • 通过将保密性与可验证性定义适配至其他隐私保护系统,统一选举与拍卖中的相关概念。
  • 通过确保正确性与隐私均得到数学保证并可由各方验证,提升电子投票系统的可信度。

提出的方法

  • 提出一个使用公钥加密与零知识证明等密码原原子的形式化框架,以保障投票保密性与可验证性。
  • 提出Helios的一个变体,采用混洗网络(mixnet)对加密选票进行混洗与解密,同时提供公开可验证的正确混洗与解密证明。
  • 采用安全游戏(如BS、IV、UV)形式化定义投票保密性与个体/普遍可验证性,作为实现必须满足的属性。
  • 要求所有协议步骤——包括初始化、投票、计票与验证——均严格按照指定方式实现,并附有确保正确性与一致性的证明。
  • 结合加密、随机数(nonce)与零知识证明,使选民可验证其选票已被计入,同时任何人都可验证最终结果的正确性。
  • 将该框架扩展至密封投标拍卖等场景,通过适配出价保密性与拍卖可验证性的定义。

实验结果

研究问题

  • RQ1如何以形式化方式定义投票保密性与可验证性,以实现安全性的数学证明?
  • RQ2为何现有系统如Helios与JCJ不满足普遍可验证性,以及如何修正?
  • RQ3实现正确性与证明验证在确保安全选举方案按预期行为方面发挥何种作用?
  • RQ4相同的保密性与可验证性形式化定义能否应用于其他系统,如拍卖?
  • RQ5选民与公众如何确信公布的选举结果准确反映了所投选票,而不依赖对权威机构的信任?

主要发现

  • 本文指出,许多现有选举方案缺乏形式化安全定义,因此易受胁迫、操纵与错误结果的影响。
  • 证明了尽管Helios广受欢迎,但其原始形式不满足普遍可验证性,需经修改才能实现。
  • 提出一种使用混洗网络并附有正确混洗与解密公开可验证证明的Helios修正变体,并证明其同时满足投票保密性与普遍可验证性。
  • 作者表明,即使形式上安全的方案,若实现偏离指定协议步骤,仍可能在实践中失效,凸显实现验证的必要性。
  • 保密性与可验证性的定义可推广至选举之外,通过类似原则可构建可验证且私密的拍卖方案。
  • 形式化安全定义与证明不仅对正确性至关重要,也对公众对电子投票系统的信心不可或缺。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。