Intelligo ut Confido: Understanding, Trust and User Experience in Verifiable Receipt-Free E-Voting (long version)

Marie-Laure Zollinger,Peter B. Rønne,Steve Schneider,Peter Y. A. Ryan,Wojtek Jamroga
2024-07-18
Abstract:Voting protocols seek to provide integrity and vote privacy in elections. To achieve integrity, procedures have been proposed allowing voters to verify their vote - however this impacts both the user experience and privacy. Especially, vote verification can lead to vote-buying or coercion, if an attacker can obtain documentation, i.e. a receipt, of the cast vote. Thus, some voting protocols go further and provide mechanisms to prevent such receipts. To be effective, this so-called receipt-freeness depends on voters being able to understand and use these mechanisms. In this paper, we present a study with 300 participants which aims to evaluate the voters' experience of the receipt-freeness procedures in the e-voting protocol Selene in the context of vote-buying. This actually constitutes the first user study dealing with vote-buying in e-voting. While the usability and trust factors were rated low in the experiments, we found a positive correlation between trust and understanding.
Cryptography and Security,Human-Computer Interaction
What problem does this paper attempt to address?
The main problem that this paper attempts to solve is how to prevent vote - buying and coercion while ensuring ballot privacy in an e - voting system, and ensure that users understand and trust the receipt - freeness mechanism. Specifically: 1. **Ballot Privacy and Integrity**: Traditional voting protocols aim to provide election integrity and ballot privacy. To ensure integrity, some procedures allow voters to verify their ballots, but this may affect user experience and privacy protection. 2. **Preventing Vote - Buying and Coercion**: Ballot verification may lead to vote - buying or coercion because attackers may obtain a "receipt" of the ballot as evidence. Therefore, some voting protocols introduce the receipt - freeness mechanism to prevent this from happening. 3. **User Understanding and Trust**: The effectiveness of the receipt - freeness mechanism depends on whether voters can understand and use these mechanisms correctly. If voters do not understand these mechanisms, they may not be able to effectively utilize these security features, thus affecting the security of the election. To evaluate these issues, the author conducted a large - scale user study involving 300 participants, using the Selene e - voting protocol to test the effect of the receipt - freeness mechanism. The main objectives of the study were: - To evaluate users' understanding and trust in the receipt - freeness mechanism. - To test users' behavior when faced with a vote - buying scenario. - To explore the relationship between users' understanding and trust. Through this study, the author hopes to provide valuable insights and improvement suggestions for the design of future e - voting systems. ### Overview of Research Methods 1. **Experimental Design**: - Recruit 300 participants using the Prolific platform. - Design a game that includes a vote - buying scenario, and participants need to interact with a virtual vote - buyer. - Provide a Web application to simulate the voting and verification processes of the Selene protocol. 2. **Questionnaire Survey**: - Use the UEQ (User Experience Questionnaire) to evaluate user experience. - Design a new questionnaire to evaluate users' trust in the voting system. - Collect data on users' understanding and behavior. 3. **Data Analysis**: - Analyze the correlation between users' understanding and trust. - Conduct qualitative and quantitative analyses of users' behavior in the game. ### Main Findings - There is a positive correlation between users' understanding and trust in the receipt - freeness mechanism. - The user experience and trust scores are low, indicating that the existing receipt - freeness mechanism may have room for improvement in practical applications. - When faced with a vote - buying scenario, most users chose to maintain their voting intentions, but some users still chose to follow the requirements of the vote - buyer. ### Conclusions and Recommendations - The design of the receipt - freeness mechanism needs to be further improved to enhance user experience and trust. - In future user studies, more attention should be paid to user education and training to help users better understand complex voting mechanisms. - It is recommended to develop a more intuitive and user - friendly interface to reduce the difficulty of user operations and improve overall security. Through these research results, the author hopes to promote the further development of e - voting systems and ensure their security and reliability in practical applications.