key: 2024-tally-then-decrypt type: misc title: Championing tally-then-decrypt secrecy authors: - Ben Smyth year: 2024 description: >- This manuscript shows that verifiable voting systems require a security notion beyond individual- and universal-verifiability plus cast-as-intended keywords: voting, privacy, secrecy, anonymity, election system, electronic voting, e-voting abstract: >- Ballot secrecy is achievable with varying degrees of information leakage: At one extreme, winner-only secrecy reveals just the winning candidate. At the other, secrecy by anonymity reveals anonymised votes. I champion tally-then-decrypt secrecy for delivering on traditional privacy expectations, wherein an election reveals nothing more than a frequency distribution of voters' votes. The gulf between anonymised votes and vote frequency distributions is witnessed by mixnets revealing the contents of every individual ballot (i.e., anonymised votes), whilst homomorphically combining ballots reveals only a frequency distribution. links: - file: Smyth24-Tally-then-Decrypt.pdf text: Draft