Culnane University of Surrey
Total Page:16
File Type:pdf, Size:1020Kb
A Hybrid Touch Interface for Pr^et`aVoter Chris Culnane University of Surrey Abstract 4 we present an approach to providing accessibility, for a limited set of disabilities, whilst maintaining In this paper we propose a novel front-end for Pr^et`a the same privacy and integrity constraints found in Voter that aims to maintain the privacy and integrity traditional paper based Pr^et`aVoter. We will demon- guarantees found in the paper based version, whilst strate two different implementations of this novel ap- simultaneously improving the accessibility of Pr^et`a proach we have termed Hybrid Touch. Hybrid Touch Voter. Namely, we maintain the Pr^et`aVoter prop- combines a paper left hand side with a digitally ren- erty that no machine learns your vote, whilst provid- dered right hand side to provide the combination of ing improved accessibility. We term this new front- privacy and accessibility. In Section 5 we will discuss end Hybrid Touch and have implemented it on both a our future plans on how we will develop the approach Microsoft Surface and a multi-touch screen. Hybrid further. Touch combines the privacy benefits of paper with the accessibility benefits of a touch screen. It is this combination that provides more accessibility oppor- tunities as well as allowing Pr^et `aVoter to handle 2 The Importance of Accessi- larger and more complicated elections. Our goal is bility to develop a single unified front-end, which can be easily augmented with additional accessibility tech- In the UK there are a number of charities and pres- nology, to provide the same core interface for both sure groups that campaign for accessibility of vot- able-bodied and disabled voters. ing. After each general election they compile the Polls Apart [1] report. This report is included within the UK Electoral Commissions review of the elec- 1 Introduction tion and provides both an analysis of the current voting system and a view of the future. The 2010 The Pr^et`aVoter [17] end-to-end verifiable voting sys- report [18] had a number of interesting points and tem combines privacy and integrity guarantees into a recommendations. Of note was the conclusion that familiar paper based voting platform. However, the the government should \Ensure disabled people can accessibility of a paper based scheme is quite limit- vote independently and in secret by diversifying vot- ing, particularly when combined with the randomised ing methods...". The report highlighted the Govern- candidate ordering of Pr^et`aVoter. In this paper we ments obligations under the European Human Rights will provide a summary of the importance of accessi- Act and the UN Convention on the Rights of Persons bility and some of the constraints faced when looking with Disabilities to provide suitable facilities to allow to trial an electronic voting system in the UK. We disabled voters to vote with the same privacy and se- will describe the difficulties faced in trying to make curity guarantees afforded to able bodied voters. One a system accessible when using a paper based voting of the conclusions in the section on e-voting in [18] scheme. We highlight the trade off that is often re- was that \Our evaluation concluded that addressing quired between accessibility and privacy. In Section the complexity of these systems, without compromis- ing security, was where further effort needs to be di- scheme they may resent that the disabled voters are rected". This is the motivating factor for trying to able to utilise a different more modern looking sys- develop new techniques to allow disabled voters to tem. The segregation of voters into categories also interact with end-to-end verifiable election systems. causes problems in how you can determine who does It is recognised that this is a significant challenge. and does not count as disabled and is fundamentally The UK Electoral Commission [2] set out basic re- against the concept of providing a single unified in- quirements for those organisations wanting to trial terface. Having a single interface may not seem im- an electronic voting scheme in 2003, when trials were portant, but from the perspective of a disabled voter still being considered, in their recommendations [19]. it makes a significant difference. If a disabled voter It set out a number of minimum requirements, the is able to interact with the same system as everyone most notable two in this context are: else they are genuinely being treated as an equal to able-bodied voters. This provides a sense of value for 1. Suppliers should demonstrate they have taken both themselves and their vote and indicates their into consideration the specific needs of disabled equal status within society. people when planning and implementing all vot- Our goal is to develop a front-end that is funda- ing systems mentally the same for everyone, but that can be aug- 2. User trials with people with a diverse range mented with additional accessibility technology with- of impairments (e.g. people with visual, hear- out compromising the privacy or integrity of the un- ing, mobility, coordination and learning impair- derlying voting system. ments) should be conducted These two points highlight both the importance of 3 Existing Front-ends addressing accessibility when proposing and advocat- ing end-to-end verifiable voting schemes and the di- In this section we provide an overview of the tradi- verse forms of accessibility that need to be addressed. tional paper based front-end that is usually thought It is often accessibility for the visually impaired that of when discussing Pr^et`aVoter. We describe two gains the most attention, but the other forms of dis- alternative front-ends to Pr^et`aVoter. The touch ability such as mobility, co-ordination and learning screen interface described in Section 3.2 can provide impairments are equally important. good accessibility but it comes at the cost of privacy. Alternatively, the approach described in Section 3.3 makes use of some similar technologies to the ones we 2.1 Multiple Voting Platforms use, but does not provide additional accessibility. An often suggested solution to the problem of acces- sibility is to provide multiple platforms for voting, 3.1 Paper Based Front-end for example, have paper based voting for able-bodied voters and pure touch screen voting for disabled vot- Pr^et`aVoter has traditionally been proposed with an ers. However, there are a number of problems with all paper front-end [17]. The voter receives a paper this approach. Often the more accessible platform ballot, with a perforation down the middle, a ran- has weaker privacy guarantees, for example a touch domised candidate order on the left hand side and screen device will learn how the voter has voted. This vote boxes and an onion contained in a 2D barcode1 is in direct contravention of the requirement for dis- 1The exact contents of the onion varies depending on the abled voters to be afforded the same privacy and in- version of Pr^et`aVoter and the type of election being run. tegrity guarantees as able-bodied voters. It also acts At an abstract level it should be thought of as containing an to segregate the disabled voters and could even cre- encrypted copy of the permuted candidate names. Some ver- sion of Pr^et `aVoter have a single onion for the entire ballot, ate resentment. If the able-bodied voters are hav- others have a separate one for each candidate. In the current ing to use a less accessible, and probably less usable, Pr^et`aVoter version the encrypted contents of the onion are 2 ranked elections the task is considerably harder. The scanner must now accurately recognise handwritten numbers. Whilst recent research has shown improve- ments in handwritten number recognition [7], they still cannot offer a 100% accuracy rate. The via- bility of applying such techniques is uncertain and even a small percentage of errors could create serious bottlenecks in the polling station and possibly even undermine the trust in the system. Strategies for mitigating this can be employed, for example, having a touch screen to confirm what has been scanned in, but this raises questions over what the binding vote is: the vote on the paper or the vote submitted from the screen? It adds an additional check to the pro- cess, which is essential, and leads to the voter having to check their vote on multiple occasions, once when scanned, once on the returned receipt and then again at home on the Web Bulletin Board. It seems un- Figure 1: Example Pr^et`aVoter Ballot (the dashed likely that significant numbers of voters are going to line represents the perforation) undertake this additional workload. The greatest problem with the paper only front- end is the lack of suitable accessibility technologies. Accessibility is not just a desirable property for an on the right hand side. An example ballot can be seen election system to have, it is often a requirement. In in Figure 1. The voter fills in the right hand side with the UK, proposed systems must demonstrate a plan their vote, tears down the perforation, destroys the to provide accessibility before the Electoral Commis- left hand side and has the right hand side scanned. sion will even back the running of a trial with it [19]. The contents of the right hand side are submitted to With an all paper front-end we are in the unfortu- the Web Bulletin Board, which provides a receipt to nate position of producing a system that is less ac- prove to the voter that their vote has been accurately cessible than the current paper voting system used recorded.