While existing literature on electronic voting has extensively addressed verifiability of voting protocols, the vulnerability of electoral rolls in large public elections remains a critical concern. To ensure integrity of electoral rolls, the current practice is to either make electoral rolls public or share them with the political parties. However, this enables construction of detailed voter profiles and selective targeting and manipulation of voters, thereby undermining the fundamental principle of free and fair elections. In this paper, we study the problem of designing publicly auditable yet privacy-preserving electoral rolls. We first formulate a threat model and provide formal security definitions. We then present a protocol for creation and maintenance of electoral rolls that mitigates the threats. Eligible voters can verify their inclusion, whereas political parties and auditors can statistically audit the electoral roll. The entire electoral roll is never revealed, which prevents any large-scale systematic voter targeting and manipulation.
翻译:尽管现有关于电子投票的文献已广泛探讨了投票协议的可验证性,但在大型公共选举中选民名册的脆弱性仍是一个关键问题。为确保选民名册的完整性,当前的做法是公开选民名册或将其分享给各政党。然而,这种做法使得构建详细的选民画像、有选择性地针对和操纵选民成为可能,从而破坏了自由公平选举的基本原则。本文研究了如何设计既公开可审计又保护隐私的选民名册问题。我们首先构建了威胁模型并提供了形式化的安全定义,随后提出了一套用于创建和维护选民名册的协议以缓解这些威胁。合格选民可验证自己是否被列入名册,而政党和审计员则能对名册进行统计审计。整个选民名册从未被完全披露,从而防止了任何大规模、系统性的选民针对和操纵行为。