@techreport{Smyth14-ballot-independence-for-election-schemes, author = {Ben Smyth and David Bernhard}, title = {{Ballot secrecy and ballot independence:}} # {{ definitions and relations}}, year = {2014}, month = {October}, number = {2013/235}, institution = {Cryptology ePrint Archive}, url = {https://publications.bensmyth.com/2014-ballot-independence-for-election-schemes/}, url-pdf = {https://publications.bensmyth.com/files/Smyth14-ballot-independence.pdf}, url-bib = {https://publications.bensmyth.com/files/Smyth14-ballot-independence-for-election-schemes.bib}, url-yaml = {https://publications.bensmyth.com/files/Smyth14-ballot-independence-for-election-schemes.yml}, url-md = {https://publications.bensmyth.com/files/Smyth14-ballot-independence.md}, note = {Cryptology ePrint Archive version: https://eprint.iacr.org/2013/235}, keywords = {ballot independence, ballot secrecy, elections, election schemes, electronic voting, e-voting, Helios, controlled malleability, malleability}, abstract = {We study ballot independence for election schemes. First, we formally define ballot independence as a cryptographic game and prove that ballot secrecy implies ballot independence. Secondly, we introduce a notion of controlled malleability and prove that it is sufficient for ballot independence. We also prove that non-malleable ballots are sufficient for ballot independence. Thirdly, we prove that ballot independence is sufficient for ballot secrecy in a special case. Our results show that ballot independence is necessary in election schemes satisfying ballot secrecy. Furthermore, our sufficient conditions enable simpler proofs of ballot secrecy.} }