In Remote Electronic Voting (REV) literature, the definitions of privacy and verifiability are well established; please refer to [1] and [2].

As analyzed in [3], the current Swiss Remote Postal Voting (RPV) system does not provide any verifiability. The system mainly relies on the trusted authorities during the whole voting setup and process. Also, there are already digital systems in place that are used within the Swiss RPV context, e.g., E-Counting, or to transmit intermediate results [3]. Recent examples have shown these systems to be outdated, vulnerable, and not secure [4].  

Further, recent attacks on the Swiss RPV were documented in [5], and a different attack vector was outlined in [6]. These security issues are not surprising since REV and RPV show many open challenges [6]. 

Previous work performed at CSG also proposed a generic framework to tackle these challenges by decentralizing the processes digitally [7]. The application of cryptographic voting schemes allows the deployment of a verifiable postal voting scheme. In theory, there are cryptographic schemes (based on homomorphic encryption) proposed in [9] that can provide Ballot Tracking (just for the logistics). It is based on the Tracker system proposed in [10]. The key focus of this MAP is (i) analyzing the Swiss RPV, then (ii) proposing and (iii) developing a suitable voting protocol for the Swiss RPV. Within that context, it should be investigated how verifiability properties can be enhanced in order to enable a fully end-to-end verifiable voting scheme. The MAP’s output is a fully working Proof-of-Concept (PoC), which sees multiple components envisioned: Frontend applications allow (a) voters to register their ballot and then track it, as well as (b) frontend applications for the election authorities to administer the ballots (as well as transmit the tally). Backend components which (i) might be used for state management of the frontends and as an interface to a Distributed Ledger or Blockchain. How and in which context information should be available on a Public Bulletin Board (PBB) (check [8]) should be carefully investigated and assessed from a security perspective. Any publication of data on a PBB can bear long-term privacy issues. Commitment Consistent Encryption could be an option here [11] to be closely investigated. The prototype should be evaluated in terms of practically relevant properties (performance and scalability), security properties (Risk Assessment), and dedicated REV properties (e.g., Ballot Secrecy, End-to-End Verifiability and Accountability). The MAP will require dedicated research into cryptographic building blocks of REV and RPV, as well as RFID elements to see this prototype working.

