Ceci n’est pas une preuve
Published: 12 March 2019
The use of trapdoor commitments in Bayer-Groth proofs and the implications for the verifiability of the Scytl-SwissPost Internet voting system
Authors
- Sarah Jamie Lewis - Open Privacy Research Society
- Olivier Pereira - UCLouvain – ICTeam, B-1348 Louvain-la-Neuve, Belgium
- Vanessa Teague - The University of Melbourne, Parkville, Australia
Abstract
The implementation of the commitment scheme in the SwissPost-Scytl mixnet uses a trapdoor commitment scheme, which allows an authority who knows the trapdoor values to generate a shuffle proof transcript that passes verification but actually alters votes. We give two examples of details of how this could be used.
The first example allows the first mix to use the trapdoors to substitute votes for which it knows the randomness used to generate the encrypted vote. The second example does not even require knowledge of the random factors used to generate the votes, and could be used by the last mix in the sequence.
Note
Since the above abstract was written SwissPost & Scytl have confirmed our analysis, and the entire e-voting program was suspended after we reported a 3rd critical flaw which impacted Individual Verifiability.
Full Text: https://sarahjamielewis.com/evoting/UniversalVerifiabilitySwissPost.pdf
Support Privacy on the Margins
Everyone deserves access to privacy enhancing technologies. With your help we can research, design, audit, and deploy cutting edge technology to those who need it most.
2024/2025 Donation Goal
$44977.00
~$44,977 / $60,000
(projected based on individual and monthly pledges as of August 14th 2024)