[110725] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: PunchScan voting protocol

daemon@ATHENA.MIT.EDU (Taral)
Fri Dec 14 10:58:26 2007

Date: Thu, 13 Dec 2007 17:23:39 -0800
From: Taral <taralx@gmail.com>
To: "John Denker" <jsd@av8n.com>
Cc: cryptography@metzdowd.com
In-Reply-To: <475FF654.8060604@av8n.com>

On 12/12/07, John Denker <jsd@av8n.com> wrote:
> Several important steps in the process must be carried out in
> secret, and if there is any leakage, there is unbounded potential
> for vote-buying and voter coercion.

I've done quite a bit of work with this protocol. The protocol assumes
the existence of an Election Authority. The Authority has the master
keys required to generate certain data sets, and these keys give the
Authority the ability to associate ballot numbers with votes. Note
that this doesn't necessarily give the Authority the ability to
associate people with votes.

There are no per-ballot keys, so there is no partial exposure risk.
It's all-or-nothing.

> 1) It would be nice to see some serious cryptological protection
> of election processes and results.

> 2b) In particular I don't think PunchScan really solves "the"
> whole problem.

What is "the" whole problem? Please provide an attack model.

-- 
Taral <taralx@gmail.com>
"Please let me know if there's any further trouble I can give you."
    -- Unknown

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post