Elections and voting play a crucial role in the development of a democratic society, enabling the public to express their views and participate in the decision-making process. Voting methods have evolved from paper ballot systems to e-voting systems to preserve the integrity of votes, ensuring a secure, transparent, and verifiable process. Continuous efforts have been made to develop a secure e-voting system that eliminates fraud attempts and provides accurate voting results. In this paper, we propose the architecture of a blockchain-based e-voting system called VoteChain. Developed to support the existing voting system in the state of Palestine, VoteChain aims to provide secure e-voting with features such as auditability, verifiability, accuracy, privacy, flexibility, transparency, mobility, availability, convenience, data integrity, and distribution of authority. The work introduces a smart contract designed to meet the demands of e-voting, governing transactions, monitoring computations, enforcing acceptable usage policies, and managing data usage after transmission. The proposed system also adopts advanced cryptographic techniques to enhance security. VoteChain features a web-based interface to facilitate user interaction, providing protection against multiple or double voting to ensure the integrity of the election. Furthermore, VoteChain is designed with a user-friendly and easily accessible administrator interface for managing voters, constituencies, and candidates. It ensures equal participation rights for all voters, fostering fair and healthy competition among candidates while preserving voter anonymity. A comparative analysis demonstrates VoteChainâs advancements in privacy, security, and scalability over both traditional and blockchain-based e-voting systems.
Using the Ethereum blockchain for decentralized voting offers a secure, transparent, and tamper- resistant method for conducting online elections. This application runs on the Ethereum blockchain network, enabling participants to cast their votes and access voting results without needing any intermediaries. In this approach, votes Once information is stored on the blockchain, it cannot be altered or tampered with, ensuring transparency and trust in the recorded outcomes. Smart contracts are utilized to automate the voting process, ensuring it remains transparent and secure. The combination of blockchain technology and a decentralized system delivers a dependable and cost-efficient solution for conducting fair and trustworthy elections.
Proof-of-Authorization (PoA) consensus algorithms are widely used in permissioned blockchain networks due to their high throughput , security, and efficiency. However, PoA is susceptible to cloning attacks, where attackers copy the authenticator identity and key, thereby compromising the consensus integrity. This study proposes a novel randomized authenticator within the PoA framework to mitigate cloning attacks and solve the leader selection bottleneck. The main contributions include 1) Introducing unpredictability in leader selection through Verifiable Random Functions (VRFs) to prevent identity duplication.2) Dynamic group management using a hierarchical decentralized architecture of distributed ledgers that balances security and performance.3) Using threshold signatures to avoid a single point of failure among validators.4) Comprehensively analyzing attacks, security, randomness, and availability.5) Evaluating the effectiveness of a randomized authenticator by means of OMNET++ simulations to assess efficiency. By integrating randomness into leader selection and robust consensus design, the approach enables reliable and secure dynamic group management in decentralized networks.
Inderpreet Singh, Amandeep Kaur, Parul Agarwal, Sheikh Mohammad Idrees
Abstract Most existing e-government services are centralized and rely heavily on human control. This centralized approach makes the system more susceptible to external attacks and compromises data integrity by rogue insiders. Additionally, relying on individuals to monitor and control workflows introduces errors and corruption risks. In order to guarantee security and transparency, this study proposes an automated and decentralized online voting system that makes use of blockchain technology. Compared to conventional voting techniques, it is more efficient and cost-effective, because it eliminates the need of intermediaries. The primary goal of this research is to use blockchain technology to develop a transparent and safe online voting system. In this paper, a decentralized voting system will be developed utilizing ethereum blockchain and smart contracts to ensure the voting processâs integrity. The system can be evaluated with simulated voting data to reflect real-world scenarios, focusing on security, scalability, and user-friendliness. The study also explores potential future enhancements, such as incorporating biometric authentication to further improve accessibility and security. The insights provided will be valuable to policymakers, researchers, and practitioners involved in the development, implementation, and regulation of blockchain-based voting systems.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Matthew Sharp, Laurent Njilla, ChinâTser Huang, Tieming Geng
Advancements in blockchain technology and network technology are bringing in a new era in electronic voting systems. These systems are characterized by enhanced security, efficiency, and accessibility. In this paper, we compose a comparative analysis of blockchain-based electronic voting (e-voting) systems using blockchain technology, cryptographic techniques, counting methods, and security requirements. The core of the analysis involves a detailed examination of blockchain-based electronic voting systems, focusing on the variations in architecture, cryptographic techniques, vote counting methods, and security. We also introduce a novel blockchain-based e-voting system, which integrates advanced methodologies, including the Borda count and Condorcet method, into e-voting systems for improved accuracy and representation in vote tallying. The systemâs design features a flexible and amendable blockchain structure, ensuring robustness and security. Practical implementation on a Raspberry Pi 3 Model B+ demonstrates the systemâs feasibility and adaptability in diverse environments. Our study of the evolution of e-voting systems and the incorporation of blockchain technology contributes to the development of secure, transparent, and efficient solutions for modern democratic governance.
This article proposes a novel method for managing usage counters within an anonymous credential system, addressing the limitation of traditional anonymous credentials in tracking repeated use. The method takes advantage of blockchain technology through Smart Contracts deployed on the Ethereum network to enforce a predetermined maximum number of uses for a given credential. Users retain control over increments by providing zero-knowledge proofs (ZKPs) demonstrating private key possession and agreement on the increment value. This approach prevents replay attacks and ensures transparency and security. A prototype implementation on a private Ethereum blockchain demonstrates the feasibility and efficiency of the proposed method, paving the way for its potential deployment in real-world applications requiring both anonymity and usage tracking.
Nicolas Huber, Ralf KĂźsters, Julian Liedtke, Daniel Rausch
Abstract Electronic voting (e-voting) systems have become more prevalent in recent years, but security concerns have also increased, especially regarding the privacy and verifiability of votes. As an essential ingredient for constructing secure e-voting systems, designers often employ zero-knowledge proofs (ZKPs), allowing voters to prove their votes are valid without revealing them. Invalid votes can then be discarded to protect verifiability without compromising the privacy of valid votes. General purpose zero-knowledge proofs (GPZKPs) such as ZK-SNARKs can be used to prove arbitrary statements, including ballot validity. While a specialized ZKP that is constructed only for a specific election type/voting method, ballot format, and encryption/commitment scheme can be more efficient than a GPZKP, the flexibility offered by GPZKPs would allow for quickly constructing e-voting systems for new voting methods and new ballot formats. So far, however, the viability of GPZKPs for showing ballot validity for various ballot formats, in particular, whether and in how far they are practical for voters to compute, has only recently been investigated for ballots that are computed as Pedersen vector commitments in an ACM CCS 2022 paper by Huber et al. Here, we continue this line of research by performing a feasibility study of GPZKPs for the more common case of ballots encrypted via Exponential ElGamal encryption. Specifically, building on the work by Huber et al., we describe how the Groth16 ZK-SNARK can be instantiated to show ballot validity for arbitrary election types and ballot formats encrypted via Exponential ElGamal. As our main contribution, we implement, benchmark, and compare several such instances for a wide range of voting methods and ballot formats. Our benchmarks not only establish a basis for protocol designers to make an educated choice for or against such a GPZKP, but also show that GPZKPs are actually viable for showing ballot validity in voting systems using Exponential ElGamal.
In this paper, we propose a smart contract-based multi-candidate self-tallying voting scheme in order to guarantee the privacy of ballots in the case of multiple candidates. This scheme uses the ElGamal cryptosystem to ensure the security of the ballots, and combines it with a Distributed Encryption algorithm to make the voting scheme have self-tallying features, and guarantees the correctness of the intermediate data through zero-knowledge proofs. The experimental results show that the scheme improves the voting efficiency without compromising the security.
In recent years, a more advanced form of phishing has arisen on Ethereum, surpassing early-stage, simple transaction phishing.This new form, which we refer to as payload-based transaction phishing (PTXPHISH), manipulates smart contract interactions through the execution of malicious payloads to deceive users.PTXPHISH has rapidly emerged as a significant threat, leading to incidents that caused losses exceeding $70 million in 2023 reports.Despite its substantial impact, no previous studies have systematically explored PTXPHISH.In this paper, we present the first comprehensive study of the PTXPHISH on Ethereum.Firstly, we conduct a long-term data collection and put considerable effort into establishing the first ground-truth PTXPHISH dataset, consisting of 5,000 phishing transactions.Based on the dataset, we dissect PTXPHISH, categorizing phishing tactics into four primary categories and eleven sub-categories.Secondly, we propose a rule-based multidimensional detection approach to identify PTXPHISH, achieving an F1-score of over 99% and processing each block in an average of 390 ms.Finally, we conduct a large-scale detection spanning 300 days and discover a total of 130,637 phishing transactions on Ethereum, resulting in losses exceeding $341.9 million.Our in-depth analysis of these phishing transactions yielded valuable and insightful findings.Scammers consume approximately 13.4 ETH daily, which accounts for 12.5% of the total Ethereum gas, to propagate address poisoning scams.Additionally, our analysis reveals patterns in the cash-out process employed by phishing scammers, and we find that the top five phishing organizations are responsible for 40.7% of all losses.Furthermore, our work has made significant contributions to mitigating real-world threats.We have reported 1,726 phishing addresses to the community, accounting for 42.7% of total community contributions during the same period.Additionally, we have sent 2,539 on-chain alert messages, assisting 1,980 victims.This research serves as a valuable reference in combating the emerging PTXPHISH and safeguarding users' assets.
Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehiclesâ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle ownerâs behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individualâs private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the publicâs trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.
This study introduces an innovative blockchain-based voting system that leverages non-fungible tokens to enhance the integrity, openness, and accessibility of elections. By harnessing the decentralized nature of blockchain and the distinctive characteristics of NFTs, the proposed system aims to address common vulnerabilities in traditional voting methods. The research findings indicate that a blockchain-based voting system utilizing NFTs can substantially improve election integrity. NFTs are employed to authenticate voter identities, bolstering security and mitigating fraudulent activities. Additionally, the public blockchain ledger ensures the permanent recording of votes, promoting transparency and confidence in election outcomes. Furthermore, the internet-enabled voting approach allows participation from any location, reducing barriers to voter engagement and improving accessibility. This paper examines the technical implementation of the proposed system, including the application of smart contracts and cryptographic methods to protect the voting process. It also explores potential obstacles and areas for future investigation, highlighting the transformative potential of this approach in democratic procedures.
Roberto A. Pava-DĂaz, JesĂşs Gil-Ruiz, Danilo Alfonso LĂłpez-Sarmiento
Self-sovereign identity (SSI) embodies the fundamental human right to own and control a digital identity that grants access to public, social, and financial services. The absence of a dedicated digital identity layer in the development of the Internet has rendered SSI a significant challenge in contemporary society. Blockchain technology emerges as a promising solution by enabling the creation of decentralized and automatically verifiable identities. This study contextualizes SSI and analyzes how blockchain technology facilitates the autonomous management of digital identities. It explores nine prominent frameworks in this fieldâSovrin, uPort, Jolocom, ShoCard, Litentry, Civic, KILT, Idena, and IONâhighlighting their features, functionalities, and compliance with digital identity principles. The research concludes by identifying the challenges and opportunities in implementing these systems for digital identity management, thus contributing to the advancement of this emerging field.
Condorcet voting is widely regarded as one of the most important voting systems in social choice theory. However, it has seen little adoption in practice, due to complex tallying and the need to break ties when there is a Condorcet cycle. Several online Condorcet voting systems have been developed to perform digital tallying and tie-breaking procedures, but they require voters to completely trust the server. Additionally, many end-to-end (E2E) verifiable e-voting systems require trustworthy authorities to perform complex decryption and tallying operations. We propose VERICONDOR, the first E2E verifibbolable Condorcet e-voting system without tallying authorities. VERICONDOR allows a voter to fully verify the tallying integrity by themselves while providing strong protection of ballot secrecy. We present novel zero-knowledge proof techniques to prove the well-formedness of an encrypted ballot with exceptional efficiency. VERICONDOR supports ranking candidates with strict preference, as well as indifference. The computational cost is exceptionally efficient for strict preferences at \(\mathcal{O}(n^{2})\) per ballot for \(n\) candidates, while remaining practical for indifferences at \(\mathcal{O}(n^{3})\) . In the case of ties, we show how to apply known Condorcet methods to break them in a publicly verifiable manner. Finally, we present a proof of concept implementation and evaluate its performance.
Abstract High voter turnout in elections and referendums is desirable to ensure a robust democracy. Secure electronic voting is a vision for the future of elections and referendums. Such a system can counteract factors hindering strong voter turnout such as the requirement of physical presence during limited hours at polling stations. However, this vision brings transparency and confidentiality requirements that render the design of such solutions challenging. Specifically, the counting implementation must support reproducibility, and the choice of individual voters must remain confidential. In this paper, we propose and evaluate a novel referendum protocol that ensures transparency, confidentiality, and integrity, in trustless networks. The protocol is built by combining secure multi-party computation and distributed ledger technology, e.g., a Blockchain. The persistence and immutability of the protocol communication allow verifiability of the referendum outcome by any participant. Voters therefore do not need to trust third parties. We provide a formal description and conduct a thorough security evaluation of our proposal.
Muhammad Razali, Azrul Amri Jamal, Syed Abdullah Fadzli, Muhammad D. Zakaria ¡ 6 authors
The act of voting is an inherent and essential entitlement that is universally granted to all individuals. Electronic voting, commonly known as e-voting, is a voting method that utilises electronic equipment to facilitate and manage the process of casting and tallying votes. Electronic voting systems are employed to expedite the process of tallying ballots. Furthermore, it will reduce the amount of money needed to pay for counting staff while also reducing human error. The implementation of remote voting would greatly benefit individuals residing at a considerable distance from their designated polling location, as it would afford them the convenience of casting their vote at any given time and from any geographical area. The utilisation of blockchain technology presents novel opportunities for the creation and advancement of innovative digital services. The implementation of Blockchain-Enabled e-Voting has promise in mitigating instances of election fraud and enhancing voter accessibility. The voting process involved the utilisation of electronic devices, such as computers or smartphones, by those who met the criteria for voter eligibility. This method ensured that the voting process maintained the principle of anonymity. The significance of electronic credibility services has seen substantial development, becoming as a crucial element inside the contemporary information era. This project seeks to implement the objective of constructing an electronic voting system utilising blockchain technology. The two-level architecture ensures secure voting without relying on current (non-blockchain) technologies for redundancy. The blockchain-based voting project is made up of two components that work together to make the whole thing operate. One will be the admin, who will be in charge of creating elections, as well as adding candidates to the smart contract elections. The other type of user is the voter, who can vote for their preferred candidate and have their vote recorded on the blockchain to make it tamper-proof.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Election systems often face severe challenges regarding security and trust. Threats such as vote falsification and lack of transparency in vote counting have shaken the integrity of elections in various countries. The use of blockchain technology in e-voting has been proposed as an attractive solution to overcome this problem. Several studies use blockchain for the security of electronic voting systems. The existing methods are not resistant against impersonation attacks and man-in-the-middle attacks. This research proposes a new scheme to strengthen a blockchain-based e-voting system. The blockchain used in the proposed method is Ethereum. The proposed scheme uses the modified framework and The Goldreich-Goldwasser-Halevi (GGH) signature scheme. Digital signatures generated using Goldreich-Goldwasser-Halevi (GGH) can strengthen the identity of the message sender so that enemies cannot imitate someone. In this research, the Voter's public key and anonymous ID are used by the Voter to maintain the Voter's anonymity. Based on the experimental results, it can be concluded that the proposed scheme is stronger than the previous scheme because the probability of success in impersonating the sender with the proposed scheme using an impersonation attack and man-in-the-middle attack is small.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Voting is the primary mechanism through which DAOs, or Decentralised Autonomous Organisations, reach decisions. Although transparent, the voting process can be complex: it can involve many interacting smart contracts. The nexus of the decision-making process can be relocated and the true voter demographic obfuscated. Furthermore, DAOs can govern other DAOs - metagovernance. We present a method for identifying DAO-to-DAO metagovernance on the Ethereum blockchain. We focus on the links between DAOs and token contracts. We employ a signature-matching algorithm to flexibly handle a variety of DAO frameworks and voting schemes. Once we establish token-to-DAO relationships, we gather and process voting data to produce a list of metagovernance relationships. We apply this algorithm to an initial set of sixteen DAOs and we extend the dataset as more DAOs are identified. We produce a metagovernance network with 61 DAOs and 72 metagovernance relationships. We examine three case studies that show metagovernance of various forms: strategic, decisive, and centralised where a DAO becomes a nexus for metagovernance. We demonstrate that metagovernance obscures voting context and introduces entities driven by self-interest that can significantly influence governance. We highlight instances of metagovernance between DAOs operating on the Ethereum blockchain where current governance tools inadequately reveal such dynamics. To preserve the transparency-centric ethos of DAOs and mitigate risks associated with metagovernance, there is a pressing need for enhanced tools to address such issues.
The Ethereum blockchain-based electronic voting (e-voting) systems can emerge as a viable strategy in this era of contemporary democracies to revolutionize political elections and augment the efficacy of the electoral process. There are myriad advantages that the Ethereum blockchain has to offer, from fairness to increased voting rates. Unlike traditional voting protocols, the Ethereum blockchain can assure substantial cost savings and eliminate the necessity for electoral intermediaries. The use of the Ethereum blockchain in political contexts also ensures that elections are held with integrity while preserving the votersâ privacy. Due to its popularity, provision of smart contracts logic, and various promising advantages, this systematic review aims to examine the potential deployment of decentralized e-voting systems integrated with Ethereum blockchain technology for democratic political elections. A systematic literature review (SLR) and the PICO approach, which stands for population, intervention, control, and outcomes, were adopted in this study to systematically analyze the existing literature. Key technological approaches identified in the voting system include the hybrid blockchain and privacy-preserving score voting. Among the noteworthy findings are the following: while adoption and complexity remain challenges across numerous e-voting frameworks, scalability, end-to-end security, enhanced efficiency, and effectiveness are key benefits. An exploration into the prospective future innovations, such as the integration of artificial intelligence and big data analytics into the Ethereum blockchain, was also included to further improve the reliability of the e-voting systems. It is believed that the Ethereum blockchain has a promising transformative impact on electoral politics and democratic processes, presenting a ray of hope for future elections.
This paper explores the vulnerability of machine learning models, specifically Random Forest, Decision Tree, and K-Nearest Neighbors, to very simple single-feature adversarial attacks in the context of Ethereum fraudulent transaction detection. Through comprehensive experimentation, we investigate the impact of various adversarial attack strategies on model performance metrics, such as accuracy, precision, recall, and F1-score. Our findings, highlighting how prone those techniques are to simple attacks, are alarming, and the inconsistency in the attacks' effect on different algorithms promises ways for attack mitigation. We examine the effectiveness of different mitigation strategies, including adversarial training and enhanced feature selection, in enhancing model robustness.
Khadija Begum, Md Ariful Islam Mozumder, Moon-Il Joo, HeeâCheol Kim
The Internet of Medical Things (IoMT) has significantly advanced healthcare, but it has also brought about critical security challenges. Traditional security solutions struggle to keep pace with the dynamic and interconnected nature of IoMT systems. Machine learning (ML)-based Intrusion Detection Systems (IDS) have been increasingly adopted to counter cyberattacks, but centralized ML approaches pose privacy risks due to the single points of failure (SPoFs). Federated Learning (FL) emerges as a promising solution, enabling model updates directly on end devices without sharing private data with a central server. This study introduces the BFLIDS, a Blockchain-empowered Federated Learning-based IDS designed to enhance security and intrusion detection in IoMT networks. Our approach leverages blockchain to secure transaction records, FL to maintain data privacy by training models locally, IPFS for decentralized storage, and MongoDB for efficient data management. Ethereum smart contracts (SCs) oversee and secure all interactions and transactions within the system. We modified the FedAvg algorithm with the Kullback-Leibler divergence estimation and adaptive weight calculation to boost model accuracy and robustness against adversarial attacks. For classification, we implemented an Adaptive Max Pooling-based Convolutional Neural Network (CNN) and a modified Bidirectional Long Short-Term Memory (BiLSTM) with attention and residual connections on Edge-IIoTSet and TON-IoT datasets. We achieved accuracies of 97.43% (for CNNs and Edge-IIoTSet), 96.02% (for BiLSTM and Edge-IIoTSet), 98.21% (for CNNs and TON-IoT), and 97.42% (for BiLSTM and TON-IoT) in FL scenarios, which are competitive with centralized methods. The proposed BFLIDS effectively detects intrusions, enhancing the security and privacy of IoMT networks.
To be useful and widely accepted, automated contact tracing schemes (also called exposure notification) need to solve two seemingly contradictory problems at the same time: they need to protect the anonymity of honest users while also preventing malicious users from creating false alarms. In this paper, we provide, for the first time, an exposure notification construction that guarantees the same levels of privacy and integrity as existing schemes but with a fully malicious database (notably similar to Auerbach et al. CT-RSA 2021) without special restrictions on the adversary. We construct a new definition so that we can formally prove our construction secure. Our definition ensures the following integrity guarantees: no malicious user can cause exposure warnings in two locations at the same time and that any uploaded exposure notifications must be recent and not previously uploaded. Our construction is efficient, requiring only a single message to be broadcast at contact time no matter how many recipients are nearby. To notify contacts of potential infection, an infected user uploads data with size linear in the number of notifications, similar to other schemes. Linear upload complexity is not trivial with our assumptions and guarantees (a naive scheme would be quadratic). This linear complexity is achieved with a new primitive: zero knowledge subset proofs over commitments which is used by our "no cloning" proof protocol. We also introduce another new primitive: set commitments on equivalence classes, which makes each step of our construction more efficient. Both of these new primitives are of independent interest.
In this article, we propose zero-knowledge named proof, a stateless replay attack prevention strategy that ensures the userâs anonymity against malicious administrators. We begin with adopting the zero-knowledge set-membership proof into an authentication setting in which users would delegate their requests to an agent that obstructs the userâs identity from the administrator. This anonymous agent carries the guarantee of authenticity, which the administrator through the set-membership proof can confirm. Next, we prevent replay attacks from other parties by binding the agentâs identity to the authentication proof verifiable by the administrators. By leveraging these properties, a scalable blockchain-based authentication scheme is then built. We quantitatively evaluate the security and measure the time and monetary cost of our scheme under both ideal and realistic environments. On top of it, we provide a third-party authorization scheme derived from our authentication framework to demonstrate its real-world applicability.
Instant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters.
Qi Liang, Ning Shi, Yuâan Tan, Chunying Li ¡ 5 authors
With the widespread adoption of blockchain technology, its public ledger characteristic enhances transaction transparency but also amplifies the risk of privacy breaches. Attackers can infer usersâ real identities and behaviors by analyzing public transaction patterns and address relationships, posing a severe threat to usersâ privacy and security, and thus hindering further advancements in blockchain applications. To address this challenge, covert communication has emerged as an effective strategy for safeguarding the privacy of blockchain users and preventing information leakage. But existing blockchain-based covert communication schemes rely solely on the immutability of blockchain itself for robustness and suffer from low transmission efficiency. To tackle these issues, this paper proposes a stealthy communication model with blockchain smart contract for bidding systems. The model initiates by preprocessing sensitive information using a secret-sharing algorithm-the Shamir (t, n) threshold scheme-and subsequently embeds this information into bidding amounts, facilitating the covert transfer of sensitive data. We implemented and deployed this model on the Ethereum platform and conducted comprehensive performance evaluations. To assess the stealthiness of our approach, we employed a suite of statistical tests including the CDF, the KolmogorovâSmirnov test, Welchâs t-test and KâL divergence. These analyses confirmed that amounts carrying concealed information were statistically indistinguishable from regular transactions, thus validating the effectiveness of our solution in maintaining the anonymity and confidentiality of information transmission within the blockchain ecosystem.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques