List signature method and application to electronic voting
Abstract
A list signing method that comprises at least: - an organization phase (10) consisting, for a trusted authority (1), of defining parameters for the implementation of an anonymous electronic signature, which presents a private key and a corresponding public key, - a registration phase ( 20, 20 ') of persons on a list of authorized members to generate their own electronic signature for the members of the list, during which each person (2) to register calculates (24) a private key (xi) with the help of parameters provided by the trust authority and of parameters chosen, randomly, by the person to register, and the authority of trust delivers (25 ') to each person to register a certificate ([Ai, ei]) of member of the list, - a signature phase (30), during which a member of the list generates (35) and issues ( 36) an own signature to the members of the list, this signature being constituted so that it contains proof that the member of the list, who has issued the signature, makes known a certificate ([Ai, ei]) of member of the list and - a verification phase (40) of The issued signature comprising steps (41, 42) of applying a predefined algorithm to evidence the proof that the signature was issued by a person in possession of a member list certificate, characterized in that it also includes: - a phase of defining a sequence that consists of the trust authority (1) generating a sequence number ma used in the signature phase (30), a signature (Sigliste), generated during the signature phase, comprising a signature element (T4) that is common to all signatures issued by the same member of the list, with the same sequence number, and that contains proof that the sequence number m was used to generate the signature, the verification phase (40) also comprising a verification stage (43) of the proof that the sequence number was used to generate the signature; - a phase of revocation of a member from the list to remove a member from the list, during which the trust authority (1) removes the member to be removed from the list and updates the implementation parameters of the anonymous electronic signature , to take into account the withdrawal of the member from the list and - a certificate update phase ([Ai, ei]) of the members of the list to take into account changes in the composition of the list.

Term
Term ended
Projected expiry passed 16 July 2023, 3.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
13 claims: 3 independent, 10 dependent
- 1ES 2 360 044 T3 REIVINDICACIONES 1. - Un método de firma de lista que comprende al menos:- una fase de organización (10) que consiste, para una autoridad de confianza (1), en definir parámetros de puesta en práctica de una firma electrónica anónima, que presenta una clave privada y una clave pública correspondiente, - una fase de registro (20, 20') de personas en una lista de miembros autorizados para generar una firma electrónica propia para los miembros de la lista, en cuyo transcurso cada persona (2) a registrar calcula (24) una clave privada (xi) con la ayuda de parámetros proporcionados por la autoridad de confianza y de parámetros elegidos, de forma aleatoria, por la persona a registrar, y la autoridad de confianza entrega (25') a cada persona a registrar un certificado ([Ai, ei]) de miembro de la lista, - una fase de firma (30), en cuyo transcurso un miembro de la lista genera (35) y emite (36) una firma propia a los miembros de la lista, siendo esta firma constituida de manera que contenga una prueba de que el miembro de la lista, que ha emitido la firma, hace conocer un certificado ([Ai, e¡]) de miembro de la lista y - una fase de comprobación (40) de la firma emitida que comprende etapas (41, 42) de aplicación de un algoritmo predefinido para poner en evidencia la prueba de que la firma fue emitida por una persona en posesión de un certificado de miembro de la lista, caracterizado porque comprende, además: - una fase de definición de una secuencia que consiste en que la autoridad de confianza (1) genere un número de secuencia m a utilizar en la fase de firma (30), una firma (Sigliste), generada durante la fase de firma, que comprende un elemento de firma (T 4 ) que es común a todas las firmas emitidas por un mismo miembro de la lista, con un mismo número de secuencia, y que contiene una prueba de que el número de secuencia m fue utilizado para generar la firma, comprendiendo la fase de verificación (40), además, una etapa de verificación (43) de la prueba de que el número de secuencia fue utilizado para generar la firma;- una fase de revocación de un miembro de la lista para retirar un miembro de la lista, en cuyo transcurso la autoridad de confianza (1) retira de la lista el miembro a retirar y actualiza los parámetros de puesta en práctica de la firma electrónica anónima, para tener en cuenta la retirada del miembro de la lista y - una fase de actualización de certificados ([Ai, ei]) de los miembros de la lista para tener en cuenta modificaciones de la composición de la lista.
- 2- El método, según la reivindicación 1, caracterizado porque que la fase de organización (10) comprende la definición de un parámetro común (u) que depende de la composición de la lista, la fase de registro (20, 20') de una persona en la lista que comprende la definición de un parámetro (ui) propio de la persona a registrar, que se calcula en función del parámetro (u) que depende de la composición de la lista y que está integrado en un certificado ([Ai, ei, ui]) remitido a la persona, comprendiendo la fase de registro (20, 20') una etapa de actualización del parámetro común (u) que depende de la composición de la lista, la fase de revocación de un miembro de la lista, que comprende una etapa de modificación del parámetro común (u) que depende de la composición de la lista, para tener en cuenta la retirada del miembro de la lista, y la fase de actualización de certificados de los miembros de la lista que presenta una etapa de actualización del parámetro (ui), propio de cada miembro de la lista, para tener en cuenta modificaciones de la composición de la lista.
- 3- El método, según la reivindicación 1 o 2, caracterizado porque una firma propia a un miembro de la lista y que posee el certificado ([Ai, ei]) comprende parámetros T1, T2, T3, tales como:Ti = A,b“ (mod n), T 2 = g“ (modn), T 3 = g c 'h“ (mod n), siendo ω un número elegido, de forma aleatoria, en el momento de la fase de firma (30), y siendo b, g, h y n parámetros generales de puesta en práctica de la firma de grupo, tales como los parámetros b, g y h, no se pueden deducir los unos de los otros mediante funciones de elevación de potencia entera módulo n, por lo que el número Ai y por lo tanto, la identidad del miembro de la lista que posee el certificado ([Ai, ei]) no puede deducirse de una firma emitida por el miembro.
- 4- El método, según una de las reivindicaciones 1 a 3, caracterizado porque el número m de una secuencia, utilizado para generar una firma de lista, se calcula en función de una fecha de inicio de secuencia.
- 5- El método, según la reivindicación 4, caracterizado porque la función de cálculo del número de una secuencia es de la forma:F(d) = (7/(d)) 2 (mod n) ES 2 360 044 T3 en donde H es una función del resumen criptográfico resistente a las colisiones, d es la fecha de inicio de la secuencia y n es un parámetro general de la puesta en práctica de la firma de grupo.
- 6- El método, según una de las reivindicaciones 1 a 5, caracterizado porque una firma (Sig liste ) emitida por un miembro de la lista contiene un parámetro (T4) que se calcula en función del número de secuencia y de la clave privada (xi) del miembro signatario.
- 7- Método según la reivindicación 6,caracterizado porque el parámetro T4 de una firma emitida por un miembro de la lista y que depende del número de secuencia m y de la clave privada Xi del miembro signatario se obtiene por la fórmula siguiente:T 4 = m A| ( mot i n ) siendo n un parámetro general de puesta en práctica de la firma de grupo, y porque la firma comprende la prueba de que el parámetro T4 fue calculado con la clave privada Xi del miembro de la lista que ha emitido la firma.
- 8- Método de voto electrónico que comprende una fase de organización (50) de las elecciones, en cuyo transcurso una autoridad organizadora procede a la generación de parámetros necesarios para un escrutinio y atribuye a escrutadores de las claves que les permiten descifrar y comprobar las papeletas de voto, una fase de atribución de un derecho de firma a cada uno de los electores, una fase de voto (60) en cuyo transcurso los electores firman una papeleta de voto y una fase de recuento (70) en cuyo transcurso los escrutadores que comprueban las papeletas de voto y calculan el resultado del escrutinio en función del contenido de las papeletas de voto descifradas y válidas, caracterizado porque pone en práctica un método de firma de lista, según una de las reivindicaciones 1 a 7, para firmar las papeletas de voto, siendo cada elector registrado como miembro de una lista y siendo un número de secuencia m generado para el escrutinio, para detectar si un mismo elector ha emitido, o no, varias papeletas de voto para el escrutinio.
- 9- Método según la reivindicación 8, caracterizado porque la fase de organización (50) comprende la entrega a cada escrutador de una clave pública y de una clave privada, porque las papeletas de voto (vi) son cifradas (62) con la ayuda de una clave pública (Y) obtenida por el producto de las claves públicas (y¡) respectivas de todos los escrutadores y porque la clave privada (X) de descifrado correspondiente se obtienen calculando la suma de claves privadas (x¡) respectivas de todos los escrutadores.
- 10- Método según la reivindicación 9, caracterizado porque el cifrado(62) de las papeletas de voto se efectúa con la ayuda de un algoritmo de cifrado probabilista.
- 11- Método según una de las reivindicaciones 8 a 10, caracterizado porque las papeletas de voto emitidas por los electores se almacenan en una base de datos pública (4), porque el resultado de la comprobación y del recuento de cada papeleta de voto se guarda en la base de datos en asociación con la papeleta de voto y porque se publica la clave privada (X) de descifrado de las papeletas de voto.
- 12- Calculador para la puesta en práctica de una firma de lista, que comprende medios para:- generar parámetros de puesta en práctica de una firma electrónica anónima propia de los miembros de una lista, conteniendo los parámetros una clave privada y una clave pública correspondiente y - transmitir a cada persona (2), a registrar en la lista, parámetros a utilizar por la persona a registrar para calcular (24) una clave privada (x i ) y un certificado ([A¡, e i ]) de miembro de la lista, caracterizado porque comprende, además, medios para: - generar un número de secuencia m a utilizar por los miembros de la lista para emitir una firma anónima propia de los miembros de la lista, una firma anónima (Sigliste) emitida por un miembro de la lista que comprende un elemento de firma (T4) que es común a todas las firmas emitidas por el mismo miembro de la lista con un mismo número de secuencia, y que contiene una prueba de que el número de secuencia m fue utilizado para generar la firma;- retirar de la lista un miembro a revocar de la lista y actualizar los parámetros de puesta en práctica de la firma electrónica anónima propia de los miembros de la lista, para tener en cuenta la retirada del miembro de la lista y - actualizar los certificados ([Ai, ei]) de los miembros de la lista a cada modificación de la composición de la lista.
- 13- Calculador para la puesta en práctica de un método de voto electrónico, que comprende medios para:- generar, en el transcurso de una fase de organización de un escrutinio de los parámetros de puesta en práctica de una firma electrónica anónima propia de los miembros de una lista de electores, conteniendo los parámetros una clave privada y una clave pública correspondiente;- atribuir a los escrutadores claves que les permitan descifrar y comprobar las papeletas de voto emitidas para el escrutinio y ES 2 360 044 T3 - transmitir a cada miembro (2) de la lista de electores del escrutinio de los parámetros a utilizar por el elector para calcular (24) una clave privada (xi) y un certificado ([Ai, ei]) de miembro de la lista de electores del escrutinio, caracterizado porque comprende, además, medios para: - generar un número de secuencia m propio al escrutinio a utilizar por los miembros de la lista de electores para firmar una papeleta de voto, una firma (Sigliste) de una papeleta de voto, que comprende un elemento de firma (T4) que es común a todas las firmas emitidas con un mismo número de secuencia por un mismo miembro de la lista de electores del escrutinio y que contiene una prueba que el número de secuencia m fue utilizado para generar la firma;- retirar de la lista un elector del escrutinio a revocar y actualizar los parámetros de puesta en práctica de la firma electrónica anónima propia a los miembros de la lista de electores del escrutinio, para tener en cuenta de la retirada del elector y - actualizar los certificados ([Ai, ei]) de los electores del escrutinio a cada modificación de la composición de la lista de los electores del escrutinio. 14 - Terminal (2) para emitir una firma de lista que comprende medios para: - recibir parámetros de cálculo de una clave privada (xi);- calcular (24) la clave privada (xi) con la ayuda de los parámetros recibidos y de parámetros elegidos de forma aleatoria;- recibir (25) un certificado ([Ai, ei]) de miembro de una lista;- generar (35) una firma propia a los miembros de la lista, siendo esta firma constituida de modo que contenga una prueba de que el miembro de la lista que emitió la firma, conoce un certificado ([Ai, ei]) de miembro de la lista y - comprobar una firma emitida por un miembro de la lista aplicando un algoritmo predefinido para poner en evidencia la prueba de que la firma fue emitida por una persona en posesión de un certificado de miembro de la lista, caracterizado porque comprende, además, medios para: - recibir un número de secuencia m a utilizar en una fase de firma (30) - generar una firma (Sigliste) calculando un elemento de firma (T4) que es común a todas las firmas emitidas por un mismo miembro de la lista con un mismo número de secuencia y que contiene una prueba de que el número de secuencia m fue utilizado para generar la firma;- comprobar la prueba de que el número de secuencia m fue utilizado para generar una firma y - recibir un nuevo certificado ([Ai, ei]) de miembro de la lista a cada modificación de la composición de la lista. 15.- Terminal (2) para emitir una firma de papeleta de voto a un escrutinio, que comprende medios para: - recibir parámetros de cálculo de una clave privada (xi);- calcular (24)la clave privada (x¡) con la ayuda de los parámetros releídos y de parámetros elegidos de forma aleatoria;- recibir (25) un certificado ([Ai, e¡]) de miembro de una lista de electores del escrutinio;- generar (35) una firma de una papeleta de voto, estando esta firma constituida de modo que contenga una prueba de que el miembro de la lista, que ha emitido la firma, conoce un certificado ([A i , e i ]) de miembro de la lista de electores y - comprobar una firma de una papeleta de voto, emitida por un miembro de la lista de elector, aplicando un algoritmo predefinido para poner en evidencia la prueba de que la firma fue emitida por una persona en posesión de un certificado de miembro de la lista, caracterizado porque comprende, además, medios para: - recibir un número de secuencia m a utilizar para firmar una papeleta de voto - generar una firma (Sigliste)de una papeleta de voto calculando un elemento de firma (T4) que es común a todas las firmas emitidas por un mismo miembro de la lista de electores con un mismo número de secuencia y que contiene una prueba de que el número de secuencia m fue utilizado para generar la firma;- comprobar la prueba de que el número de secuencia m fue utilizado para generar una firma de una papeleta de voto y - recibir un nuevo certificado ([Ai, ei]) de miembro de la lista de electores a cada modificación de la composición de la lista de electores.
Independent claims13
237 paragraphs in 5 sections, as filed
ES 2 360 044 T3
DESCRIPTION
List signing method and application to electronic voting
The present invention relates to the general field of the security of services accessible by a digital data transmission network and, more specifically, the field of electronic signature.
It applies, in particular, but not exclusively to electronic voting or also to electronic petition.
The electronic signature of a message implements a relevant mechanism of so-called public key cryptography: the signatory who possesses a secret or private key and an associated public key, can provide a message signature with the help of the secret key. To verify the signature, it is enough to have the public key.
In some applications such as electronic voting, the signatory must be able to remain anonymous. For this purpose, what is known as the anonymous electronic signature has been developed, which allows, with the help of a public key, to determine whether the signatory of a message has any rights (right to sign the message, right to possess the secret key used to sign the message, etc.), preserving the anonymity of the signatory. Furthermore, in voting or electronic petition applications, each authorized person should only be able to sign once.
Among anonymous signatures, there is also what is called a blind signature, which allows a person to obtain the signature of a message from another entity, without the latter having to know the content of the message and can establish, later, the link between the signature and the identity of the signatory. This blind signature solution therefore requires the intervention of an intermediary entity that provides the signatures. In applications such as voting or electronic petition, this solution involves an authorized authority that signs the vote of each voter or the petition for each petitioner.
In addition, the concept of group signature has been made known, which allows each member of a group to provide a signature such that a verifier, possessing an appropriate public key, can verify that the signature was issued by a member of the group without be able to determine the identity of the signatory.
This concept is described, for example, in the document:
[1] A Practical and Provably Secure Coalition-Resistant Group Signature Scheme by G. Ateniese, J Camenisch, M. Joye and G. Tsudik, in M. Bellare, Editor, Advance in Cryptology - CRYPTO 2000, vol. LNCS 1880, pages 255-270, Springer-Verlag 2000.
However, in this concept, a trusted authority can lift, at any time, this anonymity and determine the identity of a person in the group who has issued a signature. In addition, this type of signature is called unreliable, that is, it does not allow determining whether or not two signatures have been issued by the same person without lifting the anonymity of the signature. Group signatures are used in many applications, such as electronic sale at auctions, electronic currency or electronic voting. The group signature does not perfectly suit the latter application, since it authorizes a trusted authority to access the identity of a signatory, and does not allow two signatures issued by the same person to be related without determining the identity of the signatory. Furthermore, document [1] does not foresee processes for the revocation of a member of the group.
To remedy this last problem, the document [2] Efficient Revocation of Anonymous Group membership Certificates and Anonymous Credentials by J. Camenisch and A. Lysyanskaya, published by Cryptologie ePrint Archive IACR 2002, plans to add to this concept a revocation process (this document it will also be published by M. Jung, Editor CRYPTO 2002, Springer-Verlag 2002). However, this solution does not provide any solution to the problems of preserving the anonymity of the signatory and the reliability of two signatures.
In an electronic voting application, it is also necessary to guarantee a security of the maximum approximation of the traditional vote, to secure the following properties.
No one should be able to know, even partially, the results of the vote before its closing. Anyone must be able to convince themselves of the validity of the final scrutiny result. Finally, an authorized authority must be able to withdraw or revoke a person's right to vote.
When it comes to offline voting, that is, using an electronic voting machine installed in a voting office, or online voting, that is, remotely, through the Internet, for example, the proposed systems currently, who use a group signature as described in document [1] and completed in document [2], do not meet these conditions, but partly the revocation of the right to sign.
On the other hand, the application of the concept of blind signature to electronic voting is a solution whose implementation is onerous, because it forces the voter to connect several times to each election. Furthermore, if the poll is transmitted poorly, it is not possible to determine who is responsible: a voter or the organizer of the poll.
In addition, in particular in the document [3] Untraceable Electronic Mail Return Addresses and Digital Pseudonym of D. Chaum, ACM 1981, the concept of mixing networks has been disclosed, each mixing network being a function that provides a list of numbers decrypted from a list of encrypted numbers, hiding the correspondence between the encrypted numbers and the decrypted numbers. Applied to electronic voting, this
ES 2 360 044 T3 technique has the significant drawback of not allowing to verify the validity of a vote without compromising the secrecy of the latter.
The document [4] A Secure and Optimal Efficient Multi-Authority Election Scheme, by Cramer, Gennaro and Schoenmakers, Eurocrypt'97, LNCS - Springer-Verlag, describes what is called homomorphic encryption that allows calculations based on numbers encrypted. Solutions based on this method are not, however, applicable to polls involving a large number of voters.
The present invention aims to eliminate this drawback. This objective is achieved by the provision of a list signing method, which comprises at least:
- an organization phase that consists, for a trusted authority, defining implementation parameters of an anonymous electronic signature, with a private key and a corresponding public key, - a phase of registration of persons in a list of authorized members to generate their own electronic signature to the members of the list, in the course of which phase each person to be registered calculates a private key with the help of parameters provided by the trusted authority and parameters chosen, randomly, by the person to be registered, and the trusted authority delivers, to each person to be registered, a certificate of member of the list, - a signature phase, during which a member of the list generates and issues their own signature to the members of the list, constructing this signature so that it contains a proof that the member of the list, who has issued the signature, knows a certificate of member of the list, and - a phase of verification of the issued signature comprising steps of applying an algorithm predefined to show proof that the signature was issued by a person in possession of a certificate of membership of the list.
According to the invention, this method further comprises:
- a phase of definition of a sequence that consists, for the trusted authority, in generating a sequence number to be used in the signing phase, a signature generated during the signing phase that includes a signature element that is common to all the signatures issued by the same member of the list with the same sequence number and containing proof that the sequence number was used to generate the signature, including the verification phase, in addition, a verification stage of proof that the sequence number was used to generate the signature;
- a phase of revocation of a member from the list to remove a member from the list, in the course of which, the trusted authority removes the member to be removed from the list and updates the implementation parameters of the anonymous electronic signature, in order to take into account the deletion of the member from the list and - a phase of updating the certificates of the members of the list to take into account changes in the composition of the list.
According to an embodiment of the invention, the organization phase comprises the definition of a common parameter, which depends on the composition of the list, the registration phase of a person in the list comprising the definition of a parameter specific to the person to be registered, which is calculated based on the parameter that depends on the composition of the list and that is integrated into the certificate sent to the person, the registration phase comprising a stage of updating the common parameter, which depends on the composition of the list, the phase of revocation of a member of the list comprising a stage of modifying the common parameter, which depends on the composition of the list, to take into account the deletion of the member from the list and presenting the phase of updating the certificates of the members of the list with a stage of updating the parameter of each member of the list to take into account the changes in the composition of the list list.
According to an embodiment of the invention, a signature for a member of the list and who possesses the certificate [A<sub>i</sub>,and<sub>i</sub>] comprises T parameters<sub>1</sub>, T<sub>2</sub>, T<sub>3</sub> such as:
Ti = Ab "(mod.n),
T<sub>2</sub> = g "(mod.n),
T3 = geih “(mod.n), where ω is a randomly chosen number at the time of the signature phase, and where b, g, h and n are general parameters for implementing the group signature, such that the parameters b, g and h cannot be deduced from each other by integer power elevation functions modulo n, so that the number Ai and, therefore, the identity of the list member who holds the certificate [Ai e ¡], Cannot be deduced from a signature issued by the member.
Preferably, the number of a sequence used to generate a list signature is calculated based on a sequence start date.
ES 2 360 044 T3
In a preferred embodiment, the function for calculating the number of a sequence is of the form:
F (d) = (H (d))<sup>2</sup> (mod.n) where H is a collision resistant cryptographic summary function, d is the start date of the sequence, and n is a general implementation parameter of the group signature.
According to an embodiment of the invention, a signature issued by a member of the list contains a parameter that is calculated based on the sequence number and the private key of the signing member.
According to an embodiment of the invention, the parameter T4 of a signature issued by a member of the list, and which depends on the sequence number my on the private key Xi of the signatory member, is obtained by the following formula:
T4 = M<sup>xi</sup> (mod. n) where n is a general parameter for implementing the group signature, and the signature comprising the proof that the parameter T4 was calculated with the private key Xi of the member of the list that issued the signature.
The invention also refers to a method of electronic voting that comprises an election organization phase, during which an organizing authority proceeds to generate the parameters necessary for a vote count and attributes keys to tellers, which allow them to decipher and verify the ballot papers, a phase of attribution of a signature right to each of the electors, a voting phase during which the voters sign a ballot paper and a counting phase, during which the tellers verify the ballot papers and calculate the result of the counting based on the content of the deciphered and valid ballots.
According to the invention, this method implements a list signing method as defined above, to sign the ballot papers, each voter being registered as a member of a list and being a sequence number generated for the scrutiny, to detect whether the same voter has issued, or not, several ballot papers for the scrutiny.
According to an embodiment of the invention, the organization phase comprises the delivery to each scrutineer of a public key and a private key, the voting ballots being encrypted with the help of a public key obtained by the product of the public keys. respective data of all the scrutineers, and the corresponding decryption private key being obtained by calculating the sum of the respective private keys of all the scrutineers.
Preferably, the encryption of the voting ballots is carried out with the aid of a probabilistic encryption algorithm.
According to an embodiment of the invention, the voting ballots cast by the voters are stored in a public database, the result of the verification and the counting of each ballot paper stored in the database in association with the ballot paper, and the private decryption key of the ballot papers that have been published.
The invention also relates to a calculator for the implementation of a list signature, comprising means for:
- generate implementation parameters of an anonymous electronic signature for the members of a list, the parameters comprising a private key and a corresponding public key, and
- transmit to each person to be registered in the list, parameters to be used by the person to be registered to calculate a private key, and a - certificate of member of the list.
According to the invention, the calculator also comprises means for:
- generate a sequence number to be used by the members of the list to issue their own anonymous signature for the members of the list, an anonymous signature issued by a member of the list that includes a signature element that is common to all the signatures issued by the same member of the list, with the same sequence number, and containing proof that the sequence number was used to generate the signature;
- Remove from the list a member to be revoked from the list, and update the parameters of implementation of the own anonymous electronic signature for the members of the list, to take into account the withdrawal of the member from the list and update the certificates of the members of the list at each modification of the composition of the list.
The invention also relates to a calculator for the implementation of an electronic voting method, comprising means for:
- generating, in the course of an organization phase of a poll, parameters for putting into practice an anonymous electronic signature for the members of a list of voters, the parameters containing a private key and a corresponding public key;
ES 2 360 044 T3
- assign key tellers that allow them to decipher and verify the ballot papers issued for the scrutiny and
- to transmit to each member of the list of voters of the poll the parameters to be used by the voter to calculate a private key, and a certificate of member of the list of voters of the poll.
According to the invention, the calculator also comprises means for:
- generate a sequence number of its own for the count to be used by the members of the voters list to sign a ballot, a signature of a ballot that includes a signature element that is common to all the signatures issued with a same sequence number for the same member of the poll voters list, and containing proof that the sequence number was used to generate the signature;
- Remove from the list a voter from the poll to be revoked, and update the parameters of implementation of the anonymous electronic signature of the members of the list of voters from the poll, to take into account the removal of the voter and
- Update the certificates of the counting voters at each modification of the composition of the list of counting voters.
The invention also relates to a terminal for issuing a list signature comprising means for:
- receive calculation parameters of a private key;
- calculate the private key with the help of the received parameters and the parameters chosen randomly;
- receive a certificate of membership from a list;
- generate their own signature for the members of the list, this signature being constituted in such a way that it contains proof that the member of the list, who has issued the signature, knows a certificate of member of the list and
- checking a signature issued by a member of the list by applying a predefined algorithm to show proof that the signature was issued by a person in possession of a certificate of a member of the list.
According to the invention, the terminal further comprises means for:
- receive a sequence number to be used in a signature phase;
- generate a signature by calculating a signature element that is common to all the signatures issued by the same member of the list, with the same sequence number and that contains a proof that the sequence number was used to generate the signature;
- check the proof that the sequence number was used to generate a signature and
- receive a new certificate of member of the list at each modification of the composition of the list.
The invention also relates to a terminal for issuing a vote ballot signature for a scrutiny, comprising means for:
- receive calculation parameters of a private key;
- calculate the private key with the help of the received parameters and randomly chosen parameters;
- receive a certificate of membership from a list of voters for the ballot;
- generate a signature of a voting ballot, this signature being constituted in such a way as to contain proof that the member of the list, who has issued the signature, knows a certificate of member of the voters list and
- verify a signature of a voting ballot, issued by a member of the voter list, applying a predefined algorithm to highlight the proof that the signature was issued by a person in possession of a certificate of membership of the list.
According to the invention, the terminal further comprises means for:
- receive a sequence number to be used to sign a ballot;
- generate a signature of a voting ballot by calculating a signature element that is common to all the signatures issued by the same member of the voters list, with the same sequence number, and that contains proof that the sequence number was used to generate the signature;
- verify proof that the sequence number was used to generate a signature on a ballot paper and
ES 2 360 044 T3 - receive a new certificate of member of the voters list at each modification of the composition of the voters list.
A preferred embodiment of the invention will be described below, by way of non-limiting example, with reference to the attached drawings where:
Figure 1 represents a system that allows the implementation of list signing and electronic voting methods, according to the invention;
Figures 2 to 8 illustrate, in the form of flow charts, the different procedures carried out in accordance with the methods of signing the list and electronic voting, according to the invention.
The present invention provides a method of signing the list, where all authorized persons, that is, those who appear on the list, can provide a signature that is anonymous, and regardless of whether it is capable of verifying the validity of the signature. without having access to the identity of the list member who signed.
Such a method can be put into practice in the system represented in Figure 1. This system has terminals 2 made available to users and connected to a digital data transmission network 5, such as the Internet network. Each terminal 2 is advantageously connected to an integrated circuit card reader 8 7. Through the network 5, users can connect to a server 6 that gives access to information, for example, stored in a database 4. This system further comprises a computer 1 of a trusted authority that delivers, in particular, the integrated circuit cards 7 to the users.
The list signature method, according to the invention, takes up the following procedures in the group signature method, described in the reference document [1]:
- a procedure for organizing a group of signatories, which consists of establishing the different parameters and public keys that are needed, - a registration procedure, where a person to be registered in the group receives a signing right from a trusted authority , i.e. an authorized private key and certificate, - a signature procedure proper in the course of which a person, who has the right to sign, signs a message and - a verification procedure that consists of applying a signature verification algorithm to verify that the signature has been provided by a person who has a signature right.
The invention also provides a provision to guarantee the anonymity of a signatory, even before a trusted authority, as well as a procedure for organizing a sequence, which consists of defining a sequence number to be used to generate list signatures, comprising in addition, verification of a signature, a step of verifying that the signature is unique for a given sequence number.
The method according to the invention may further comprise a revocation procedure, as defined in the reference document [2]. With the help of this revocation procedure, a trusted authority can withdraw, from a member of the list, the signing rights that were previously attributed to him, based on the identity of the member. The establishment of this possibility of revocation implies the execution by the members of the list of an update procedure, during which the members of the list update their certificates to take into account the modifications (additions or withdrawals) made in the list of the persons authorized to sign.
Figure 2 illustrates the different stages of the organization procedure 10 executed in the computer 1 of the trusted authority.
According to the reference document [1], this procedure consists of choosing, 11, the following integers:
<img file="ES2360044T3_D0001.tif" />
<img file="ES2360044T3_D0002.tif" />
which are lengths of integers in numbers of bits, with:
<img file="ES2360044T3_D0003.tif" />
and in defining the following sets of integers:
ES 2 360 044 T3
Λ =] 2<sup>λ1</sup> - 2<sup>λ2</sup>, 2<sup>λ</sup>* + 2<sup>λ2</sup>[ Y
Γ =] 2<sup>Υ1</sup> - 2<sup>Υ2</sup>, 2<sup>γι</sup> + 2<sup>Υ2</sup>[.
This procedure also consists of choosing a collision-resistant cryptographic summary function H such that a binary sequence of any specified length {0, 1} * is transformed into a binary sequence of specified length k {0,1}<sup>k</sup>.
Next, the calculator 1 of the trust authority generates, randomly, in stage 12, prime numbers p 'and q' of magnitude Ip, such that p = 2p '+ 1 and q = 2q' + 1 are also prime numbers . It then calculates, in step 13, the modulus n = pq and generates, at random, in step 14, integers a, a0, b, g and h in the set QR (n) of the quadratic residues of n, that is, the set of integers y such that y = x<sup>2 </sup>(mod.n), where x is an integer. It is considered, then, that the public key PK of the trusted authority is constituted by the sequence of integers (n, a, a<sub>0</sub>, b, g, h) and that the private key of the latter is made up of the sequence of integers (p ', q').
To be registered by the trusted authority, a user, who wishes to become a member of the list, executes on his terminal 2 the procedure 20 illustrated in Figure 3. Executing this procedure establishes a dialogue with the computer 1 of the trusted authority, which then executes a procedure 20 '. The method comprises, first of all, a stage 21 of random generation of integers X<sub>l</sub> and r, respectively, in the intervals] 0.2 ^<sup>2</sup> [y] 0, n<sup>2</sup> [. From these integers, we calculate 22 an integer C1 such that:
Cj = g<sup>x</sup>'h<sup>r</sup>(modn) (5)
In stage 23, the U test of the knowledge of two numbers α and β is established (that is,
<img file="ES2360044T3_D0004.tif" />
lyr) such that
C1 = gOi<sup>13</sup> (mod n).
Such a test is constituted, for example, by randomly choosing two integers n and r2 from the set of signed binary numbers in s (21p + k) bits, indicated as follows:
<img file="ES2360044T3_D0005.tif" />
, and calculating the numbers di = g<sup>rl</sup>h<sup>Q</sup> (mod n)>
c = / í (g || h || C<sub>1</sub>|| di), where the symbol || represents the concatenation operator,
Yes! = n -ca, s<sub>2</sub>= r<sub>2</sub>-cp.
(6) (7) (S) (9) where s1 and s2 are relative integers.
The test U is then equal to (c, s1, s2, C1).
The number C1 and the test U are then sent to the trusted authority the test U and that C<sub>1</sub> it is found in the set QR (n) of the quadratic residuals of n.
which verifies, at stage 21 '
In the preceding example, the verification of the U test consists of calculating:
<img file="ES2360044T3_D0006.tif" />
The test is verified if c '= cy if s1 and s2 belong to the set ± {0<sub>s</sub> ij<sup>AND</sup><<sup>2l</sup>p<sup>+ k</sup>)<sup>+1</sup>
If this is the case, the trusted authority's calculator 1 randomly generates 22 'two integers a<sub>i</sub>, β, in the interval] 0.2<sup>λ2</sup>[, and sends these numbers to the user's terminal 2. In procedure 20, the user terminal then calculates in step 24 the integers xi and C2 using the following formulas:
ES 2 360 044 T3 ^ = 2 ^ 0.5 ^ + 01 (1110 (12 ^)), and (12)
C2 = a<sup>x</sup>'(ínodn). (13)
Then, in step 25, build the following tests (for example, according to the same principle as test U):
- the test V of knowing a number α that belongs to the set Λ such that:
C<sub>2</sub> = a<sup>to</sup> (mod n)
<img file="ES2360044T3_D0007.tif" />
β e] - 2 '·<sup>2</sup>, 2<sup>h</sup>-[ <sub>Y</sub> - the W test of knowing three numbers β, γ, δ such that
<img file="ES2360044T3_D0008.tif" />
C<sub>2</sub> and the tests V and W are then sent to the calculator 1 of the trusted authority which verifies 23 'tests V and W, and that C2 belongs to the set QR (n). If this is the case, generate 24 ', randomly, a prime number e, that belongs to the set Γ and apply the following formula:
1 / eAi = (C<sub>2</sub>to<sub>0</sub>) '(modn) (17) and returns to the user the integers Ai and ei considered as a certificate [Ai, ej of the user's membership in the list.
The calculator 1 then creates 26 'a new entry in a table of the members of the list, for example in database 4, where it stores the certificate [Ai, eg in view of modifications of the list (for example, revocation of members) and, preferably, the messages exchanged between the trusted authority and the user during this user registration procedure.
On the other hand, the user can verify 26 the authenticity of the received certificate by verifying that the following equation is satisfied:
to<sup>Xi</sup>to<sub>0</sub>= A®<sup>í</sup>(modn) (18)
At the end of this registration procedure 20, the user has a private key x<sub>i</sub> and a certificate [A<sub>i</sub>, e<sub>i</sub>] of list member, which are memorized, for example, on an integrated circuit board 7.
With the help of such a certificate, the user can generate a signature of a message M belonging to the set {0, 1} *.
For this purpose, the trusted authority publishes, according to the invention, a sequence number m, chosen randomly from the set QR (n). This number should be used by members of the list to sign a message during a given sequence. The respective numbers of different sequences must not be able to be linked. In particular, it must be impossible to calculate a discrete logarithm of a given sequence number, with respect to the base of another sequence number, that is, it must not be possible, in practice, to calculate integers x and y such that: m<sup>x </sup>= m<sup>,Y</sup> (mod n), where m and m 'sequence numbers.
This sequence number m can be calculated based on the sequence start date: m = F (date). This function F is chosen, for example, equal to:
F (d) = (/ T (d))<sup>2</sup> (mod n) (19) where H 'is a collision resistant cryptographic digest function, such as a binary sequence of any indicated length {θ, 1}, is transformed into a binary sequence of indicated length 21p {θ , 1}<sup>twenty-one p</sup> . Therefore, it is easy to check the validity of the sequence number by applying formula (19).
The procedure for signing a message is designed to allow, in particular, a user to demonstrate that they know a member certificate and member private key and that they are using the correct sequence number.
To sign a message M, a member of the list must execute, for example, on his integrated circuit card 7, connected to a terminal 2 and memorizing his certificate [Ai, ei] and his private key Xi, a signing procedure 30 ,
ES 2 360 044 T3 as illustrated in Figure 4. This method comprises, first of all, a step 31 of random generation of a number ω belonging to the set {θ, 1}<sup>21</sup> ” .
In addition, it includes a step 32 that consists of calculating the following numbers from ω:
Ti = A¡b® (mod n),
T<sub>2</sub> = g<sup>ra</sup> (mod n),
T<sub>3</sub> = g<sup>ei</sup>h® (mod n).
(20) (21) (22)
In accordance with the invention, the following number is also calculated:
T4 <sup>_ mX</sup>'(mod n) (23)
In the next step 33, the numbers ri are generated in a random way in the set of numbers ρΑ, + ιλ -ι / n 1 utoto) + ín 1-1 ^<sub>2</sub>+ k) binary, signed, in bits, indicated, r<sub>2</sub> in the set <sup>!</sup>, r<sub>3</sub> in the set and r4 in the set - (θ: O <sup>P</sup> . Then, in step 34, the following quantities are calculated:
di = T / '/ Ca<sup>12</sup>/<sup>3</sup>) (mod n) d<sub>2</sub> = T? / ^ (Mod n) d<sub>3</sub> = g<sup>r4</sup> (mod n) d<sub>4</sub> = g<sup>n</sup>h<sup>r4</sup> (mod n) (24) (25) (26) (27)
According to the invention, the following number is also calculated:
d<sub>5</sub> - m '<sup>2</sup> (mod n)
<img file="ES2360044T3_D0009.tif" />
Then, in step 35, the following numbers are calculated:
<img file="ES2360044T3_D0010.tif" />
where || represents the concatenation operation, s<sub>t</sub> = ri-c (ei-2<sup>Y1</sup>), s<sub>2</sub> = r<sub>2</sub> - c (x¡ - 2<sup>λ1</sup>), s<sub>3</sub>= r<sub>3</sub>-ceiO,
S4 = Γ<sub>2</sub> “ <sup>C0)</sup>>
(30) (31) (32) (33) where sl, s2, s3, s4 are relative integers.
The signature is, at the end, made up of the following set of numbers:
(c, Si, S<sub>2</sub>, S<sub>3</sub>, S4, Tj, T2 »T<sub>3</sub>, T4).
(34) that is broadcast, for example, by network 5.
The verification of a signature of an M message is carried out by executing the procedure 40 illustrated in Figure 5. This procedure comprises, first of all, in step 41, the calculation of the following numbers:
ES 2 360 044 T3 t<sub>1</sub>= ajTr<sup>2</sup>’<sup>,</sup>/(to'''<sup>C2M</sup>b<sup>S)</sup>) (modn) to-T ^<sup>2</sup> / g<sup>Yes</sup>(modn) t<sub>3</sub> = T2g<sup>S4</sup>(modn) (35) (36) (37)
<img file="ES2360044T3_D0011.tif" />
According to the invention. It also includes the calculation of the following numbers:
t ^ TÍm ^ 'ímodn) (39) c' = «(mllblIglIhllaollalIT ^ I ^ IITjllT.Iltdltjll ^ llUlItsllM) (40)
The signature is authentic if the following conditions are verified in step 42:
C * = C <sub>S1</sub> G ± {0, s<sub>2</sub> e ± {0, s<sub>3</sub>e ± {0, l}<sup>6 (rl + 21</sup>P<sup>+ fcflH</sup>, s<sub>4</sub> e + {0, (41) (42) (43) (44) (45)
If these conditions are not met, the signature is invalid (step 45).
Furthermore, by accessing all the signatures that were issued during a given sequence, for example in database 4, it can be easily verified, in step 43, with the help of the T4 parameter, if a member of the list has signed several times: all signatures issued by a member of the list comprise a T4 parameter that has the same value for a given sequence number.
It should also be noted that a member cannot cheat by using another value because T4 is closely tied to T1. Indeed, the calculation formula for T1 can also be written as follows:
lf<sup>i</sup>= a<sub>0</sub>to<sup>x¡</sup>b®<sup>ei</sup>(modn) (46)
If T4 is already in the set of signatures issued for a given sequence number, it follows that the signature was already issued by a member of the list for this sequence number (step 46).
To include a possibility to revoke a member of the list, the method, just described, can be modified as follows.
The list organization procedure 10 further comprises, in step 14, the random choice of a number u, which belongs to the set QR (n), and the definition of two sets E<sub>to</sub>dd and Edel that are initially empty.
The public key PK of the trusted authority is then made up of the sequence of integers (n, a, a0, b, g, h, u) and sets Eadd and Edel.
During the registration procedure 20, 20 ', the calculator 1 of the trust authority attributes, in step 25', the parameter u¡ to the new member U¡ of the list, this parameter being such that u¡ = u, and updates the value of the u parameter by substituting this value for u<sup>ei</sup>.
The certificate of the new member then regroups the integers Ai, e¡ yu¡, this certificate being memorized, in step 26 ', for future modifications and is transmitted to the new member.
The trusted authority also enters the number ei assigned to the new member in the Eadd set.
Upon receipt of their certificate, the new member further verifies that:
ES 2 360 044 T3 u¡<sup>and</sup>'= u (mod n) (47)
The other members Uj of the list must then execute an update procedure to take into account the arrival of the new member and therefore the modification of the list parameter u. This procedure consists of recalculating its parameter uj as follows:
(48)
In this way, the relation (47) is always verified for all the pairs (uj, ej) of all the members of the list.
The revocation procedure of a Uk member of the list, whose certificate is (Ak, ek, uk) consists, for the trusted authority, in modifying the u parameter as follows:
u = u<sup>1 / ek</sup> (mod n) and in introducing the parameter ek in the Edel set.
In addition, each non-revoked member Uj of the list must take into account this revocation (change of
u) by recalculating its parameter uj as follows:
u¡ = Uj<sup>b</sup><sub>or</sub><sup>to</sup> (mod n) ^ 0) where a and b such that aej + bek = 1
To determine a and b, it is enough to apply the extended Euclidean algorithm, which consists of carrying out a series of Euclidean divisions.
It should be noted that the revoked member (which has ek) cannot determine a and b with the help of formula (50), which becomes ek (a + b) = 1, and therefore recalculate the parameter uk.
During the procedure 30 for the signature by a member of the list, it is also necessary, in step 31, to choose, at random, the numbers wi, W2 and W3 of binary length equal to 21p, that is, that belongs to the set {ü, 1}<sup>21</sup> ”, And calculate, in step 32, the following numbers:
<img file="ES2360044T3_D0012.tif" />
<img file="ES2360044T3_D0013.tif" />
In addition, it is necessary, in step 33, to randomly choose numbers 15, re, r<sub>7</sub> belonging to the set + Í0 1 vfri<sup>+2,</sup>p<sup>+ fc + 1</sup>>
and numbers re and rg that belong to the set and then, calculate, in step 34, the following numbers:
di = g<sup>n</sup>h<sup>T5</sup> (mod n) d? = g ^ h<sup>17</sup> (mod n) do = T<sub>6</sub><sup>ri</sup>/ h<sup>rg</sup>(mod n) d<sub>9</sub> = Tv ^ / Cg ^ h ^) (mod n) (54) (55) (56) (57)
The number c then includes the following elements:
<img file="ES2360044T3_D0014.tif" />
It is necessary, then, to calculate in step 35:
ES 2 360 044 T3 s<sub>5</sub> r<sub>5</sub> - cwi s<sub>6</sub> = r<sub>6</sub> - cw<sub>2 </sub>s<sub>7</sub> = r<sub>7</sub> - cw<sub>3 </sub>sg = r<sub>8</sub> - ce¡w<sub>2</sub> s<sub>9</sub> = r<sub>9</sub> - ceiW<sub>3</sub> (59) (60) (61) (62) (63)
The signature is, then, made up of the following set of numbers:
(c, Yes, s<sub>2</sub>, s<sub>3</sub>, s<sub>4</sub>, s<sub>5</sub>, S6, s<sub>7</sub>, s<sub>8</sub>, s<sub>9</sub>, T<sub>b</sub> T<sub>2</sub>, T3, T<sub>4</sub> T<sub>5</sub>, T<sub>6</sub>, T<sub>7</sub>). (64)
The procedure 40 for verifying a signature then further comprises the calculation of the following numbers in step 41:
t<sub>6</sub>= T<sub>5</sub><sup>c</sup>g<sup>S1 c2</sup> h<sup>Yes</sup>(modn) t7-T7 g<sup>S6</sup>h<sup>S7</sup>(modn) t8 = u<sup>C</sup>T6<sup>C</sup>g<sup>S1_c2n</sup>/ h<sup>S8</sup>(modn) t9 = T<sub>7</sub><sup>1_c2</sup> / (g<sup>S8</sup>h<sup>S9</sup>) (modn) (65) (66) (67) (68)
<img file="ES2360044T3_D0015.tif" />
The signature is authentic if the following supplementary conditions are verified in step 42:
s<sub>5</sub> e ± {0, s<sub>6</sub> e ± {0, s<sub>7</sub> e ± {0, s<sub>8</sub>e ± {0<sub>s</sub>l) ^<sup>+ 2l</sup>^<sup>,)+,</sup>et s<sub>9</sub> e ± {0, (70) (71) (72) (73) (74)
It should be noted that, contrary to the group signature described in document [1], it is not possible, for the trusted authority, to rediscover the identity of a signatory, that is, the Ai number of the signatory's certificate from a signature of list, as described. Indeed, contrary to the method described in this document, the trusted authority does not use a private key x to generate the parameter b and therefore the number Ai cannot be derived from T1 and T2.
Also, the signature generated by a revoked member U<sub>k</sub> invalid will be detected. Indeed, the parameter T<sub>6 </sub>makes intervene the parameter uk that was determined from the common parameter u, and the parameter t<sub>8</sub>, which is calculated to verify the signature, also involves the parameter u that was modified as a result of the revocation of member k. It follows that, at the time of signature verification, the parameters T6 and t8 are inconsistent and, therefore, that the equality between c and c 'cannot be verified by the signature of member k.
The list signing method, just described, can be applied to an electronic voting method. The electronic voting method, according to the invention, comprises several phases, the execution of which of the list signing method procedures is described below.
This method involves the intervention of a trusted authority 1 organizing the elections, which executes, for this purpose, a procedure 50 for organizing the vote. This procedure consists of generating the data necessary for the proper conduct of the elections, a public database accessible to all, where the ballot papers are collected. In the course of organizing the scrutiny, scrutineers are also appointed who will be in charge of counting the votes and determining the result of the election.
The organizing authority proceeds, first of all, to the generation of the different parameters necessary for the establishment of a list signature, executing the procedure 10 for organizing a list signature. Voters must then register in advance, for example in a mayor's office, on an electoral list in such a way that they
ES 2 360 044 T3 that receives all the necessary data, namely a private key xi and a certificate (Ai, ei, ui), to generate a list signature. With the help of these parameters, voters can participate in all future elections. This registration procedure can, for example, be carried out between an integrated circuit card 7 and a terminal 2, the integrated circuit card memorizing, at the end of the procedure, the voter's certificate.
Before an election, the organizing authority proceeds to update the electoral lists by executing procedure 20, 20 'for the newly registered voters, and withdrawing (revoking) the rights to sign the list of all persons excluded from the voter registers. (for example, people who have left the constituency or deprived of their civic rights). These revocations are made by executing the revocation procedure described above. In step 51 of procedure 50, the organizing authority also publishes a sequence number m necessary for the establishment of a new list signature sequence, so that voters are prevented from voting (signing) twice in this election .
On the other hand, the scrutineers will proceed to create 52 the necessary public / private key pairs, in such a way that all must cooperate to be able to decrypt a message encrypted with the public key. For this purpose, the established cryptographic system is chosen so that a voter is allowed to encrypt a message (ballot) with the help of at least one public key, imposing the cooperation of all tellers to use the private key (s) and thus decipher the message.
The distribution of the private decryption keys among all the scrutiners can be carried out as follows.
G is considered to be a generator of the cyclic group G. A respective private key xi is assigned to each scrutineer i that calculates the number y, belonging to G such that:
(75)
<img file="ES2360044T3_D0016.tif" />
The public key Y to be used by voters is obtained by the following formula:
<img file="ES2360044T3_D0017.tif" />
and the corresponding private key X shared by all scrutiners i is the following:
<img file="ES2360044T3_D0018.tif" />
(77)
An analogous result can be reached by carrying out an encryption using all the respective public keys of the scrutineers, the decryption requiring knowledge of all the corresponding private keys.
Before going to vote, each voter must update their list signing certificate, in accordance with the modification procedure described above, with the help of the previously published parameters. If the voter is not excluded from the electoral lists, this modification may be made.
During the opening of the voting offices, each voter issues a ballot paper by executing, in a terminal, a procedure 60. In step 61, the voter selects his vote vi and encrypts the latter with the help of the public key of the tellers to obtain an encrypted vote Di. He then signs the encrypted vote with the help of the list signing method to obtain a Yes signature. The ballot made up of the set (Di, Si) of the vote and the signature, is then published, anonymously, in a public database 4.
In step 62, the vote is encrypted using a probabilistic encryption algorithm (that is, the probability that two encryptions of the same message are identical is almost zero), such as, for example, the El Gamal algorithm or by Paillier. If the El Gamal algorithm is applied, the encryption is carried out by calculating the following numbers:
<img file="ES2360044T3_D0019.tif" />
where r is a random element. The encrypted vote vj is then constituted by the pair Dj = (aj, bj). The voter Ej determines 63, then, the list signature of the encrypted vote, the list signature being as described above, executing the procedure 30 by his integrated circuit card 7, which is then transmitted to terminal 2.
The voter Ej has thus generated his ballot paper (Dj, Sj) which sends 64 to the public database 4 by means of an anonymous transmission channel, that is to say, preventing a transmitted message from being related to the issuer of the latter. The voter can, for this purpose, use a public terminal or a network of mixers.
At the end of the scrutiny, the scrutineers count the scrutiny by executing procedure 70 on terminal 3. This procedure consists, above all, of generating 71 the private decryption key X from its keys
ES 2 360 044 T3 respective private xi and with the help of formula (77). Then, in step 72, they access the public database 4 of the voting ballots to obtain the ballots (Di, Si) and to decrypt them.
The actual decryption of the ballot papers consists for each ballot issued (step 73) to verify 74 the signature Yes by executing the above-described list signature verification procedure and if the signature is valid and unique (step 75) , to decrypt 76 the encrypted vote Dj by applying the following formula:
<img file="ES2360044T3_D0020.tif" />
The votes vj thus deciphered and verified, with the result of the corresponding verification, are entered 77 in the database 4 of the ballots, in association with the ballot (Dj, Sj).
Decryption private key X is also published to allow everyone to verify the ballot count.
Once all the ballots have been counted, this procedure 70 calculates, in step 78, the result of the election and updates the public database of the ballots, introducing in it this result and, if necessary, the private key decryption X.
It is easy to verify that the aforementioned properties, necessary for the establishment of an electronic voting system, are verified by the method described above. Indeed, each voter can only vote once since it is easy to find, in the database, two signatures issued by the same voter for the same ballot (for the same sequence number). In this case, the tellers may disregard the two votes or count only one vote if they are identical.
As an alternative, it can be envisaged that, in step 64 of entering a vote in database 4, it is verified that the vote cast by the voter no longer appears in the database, by searching in it for its own parameter T4 of the voter. If, in this way, it is detected that the voter has already voted for this count, the new vote will not be entered in the database 4.
Consequently, it is not possible to start the counting of the ballots before the end of the count if at least one of the tellers respects the rule, since the presence of all the tellers is required to count a ballot. Finally, the result of the election is verifiable by all, since the scrutineers provide, in the database, all the necessary elements (in particular, the private counting key) to proceed with such a verification and that the verification of a signature is accessible to all, using the public key PK = (n, a, a0, b, g, h, u) of the trusted authority. In this way, any trusted person will be able to carry out the count in the same way as the tellers and therefore, it will be possible to make sure that it was done correctly.
Of course, the tellers' keys will be out of date at the end of the count, since they were made public.
Contents5
24 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24
11 members in 8 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0209218 | France | A | |
| 0209218 | France | A | |
| FR20020009218 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| FR2842680A1 | France | A1 | |
| WO2004010642A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003267523A1 | Australia | A1 | |
| EP1523824A1 | European Patent Office (EPO) | A1 | |
| US2006015737A1 | United States of America | A1 | |
| US7657738B2 | United States of America | B2 | |
| EP1523824B1 | European Patent Office (EPO) | B1 | |
| AT497659T | Austria | T | |
| ATE497659T1 | Austria | T1 | |
| DE60335953D1 | Germany | D1 | |
| ES2360044T3This record | Spain | T3 |
Numbers
- Publication
- 2360044
- Publication, DOCDB
- 2360044
- Publication, EPODOC
- ES2360044T
- Application
- 3748214
- Application, DOCDB
- 03748214
- Application, EPODOC
- ES20030748214T
Titles2
- Spanish
- METODO DE FIRMA DE LISTA Y APLICACION AL VOTO ELECTRONICO.
- English
- SIGNATURE METHOD OF LIST AND APPLICATION TO ELECTRONIC VOTE.
Classification
- CPC, 5
- H04L9/3263
- G06Q20/383
- H04L9/3255
- H04L2209/42
- H04L2209/463
- IPC, 1
- H04L9 32