Ceci n’est pas une preuve

Published: 12 March 2019

The use of trapdoor commitments in Bayer-Groth proofs and the implications for the verifiability of the Scytl-SwissPost Internet voting system

Authors

  • Sarah Jamie Lewis - Open Privacy Research Society
  • Olivier Pereira - UCLouvain – ICTeam, B-1348 Louvain-la-Neuve, Belgium
  • Vanessa Teague - The University of Melbourne, Parkville, Australia

Abstract

The implementation of the commitment scheme in the SwissPost-Scytl mixnet uses a trapdoor commitment scheme, which allows an authority who knows the trapdoor values to generate a shuffle proof transcript that passes verification but actually alters votes. We give two examples of details of how this could be used.

The first example allows the first mix to use the trapdoors to substitute votes for which it knows the randomness used to generate the encrypted vote. The second example does not even require knowledge of the random factors used to generate the votes, and could be used by the last mix in the sequence.

Note

Since the above abstract was written SwissPost & Scytl have confirmed our analysis, and the entire e-voting program was suspended after we reported a 3rd critical flaw which impacted Individual Verifiability.

Full Text: https://sarahjamielewis.com/evoting/UniversalVerifiabilitySwissPost.pdf


Support Privacy on the Margins

Everyone deserves access to privacy enhancing technologies. With your help we can research, design, audit, and deploy cutting edge technology to those who need it most.

2024/2025 Donation Goal

$44977.00

~$44,977 / $60,000

(projected based on individual and monthly pledges as of August 14th 2024)