Paper 2025/1625

A Practical and Fully Distributed E-Voting Protocol for the Swiss Context

Véronique Cortier, University of Lorraine, French National Centre for Scientific Research, Inria Nancy - Grand-Est research centre
Alexandre Debant, University of Lorraine, French National Centre for Scientific Research, Inria Nancy - Grand-Est research centre
Henri Devillez, University of Lorraine, French National Centre for Scientific Research, Inria Nancy - Grand-Est research centre
Olivier Esseiva, Swiss Post
Pierrick Gaudry, University of Lorraine, French National Centre for Scientific Research, Inria Nancy - Grand-Est research centre
Audhild Høgåsen, Swiss Post
Chiara Spadafora, Swiss Post, Università di Trento
Abstract

Internet voting aims at guaranteeing both vote secrecy and verifiability. Advanced deployed systems, such as in Estonia or Switzerland, put a strong emphasis on cast-as-intended: even when a voter uses a corrupt device, they should be able to check that their intended vote is included in the tally. One approach relies on return codes, written on a voting card. This enables cast-as-intended even when the voter uses a single device that may be corrupted. While convenient for voters, this requires to generate the codes in a secure manner. This approach is deployed in Switzerland but the current system requires a single trusted setup authority: an offline component that is assumed to correctly generate the voting data. We propose a novel protocol that allows to distribute the trust during the setup. At the heart of our system lies an asymmetric protocol where several parties create the voting material, while allowing one of these parties to remain offline during the voting phase. Usability constraints are taken into account in our design, both in terms of computational complexity (linear setup and tally) and in terms of user experience (we ask the voter to type a high-entropy string only once). Our protocol is therefore a candidate for the next generation e-voting protocol in Switzerland. We provide an implementation of our protocol, demonstrating its practicability. Moreover, we formally prove vote privacy and verifiability. Our analysis takes into account the presence of short codes that an attacker can guess with non-negligible probability and reveals that making a significant change to the result remains exponentially hard.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
evotingsymbolic models
Contact author(s)
veronique cortier @ loria fr
alexandre debant @ inria fr
henri devillez @ loria fr
olivier esseiva @ post ch
pierrick gaudry @ loria fr
audhild hoegaasen @ post ch
chiara spadafora @ unitn it
History
2026-09-16: revised
2025-09-09: received
See all versions
Short URL
https://ia.cr/2025/1625
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1625,
      author = {Véronique Cortier and Alexandre Debant and Henri Devillez and Olivier Esseiva and Pierrick Gaudry and Audhild Høgåsen and Chiara Spadafora},
      title = {A Practical and Fully Distributed E-Voting Protocol for the Swiss Context},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1625},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1625}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.