Ballot secrecy
Can identity and vote really be separated so no actor can reconstruct the connection?
Independent concept · Digital voting
A concept for how municipal, regional, and parliamentary elections could potentially be conducted digitally at polling stations without connecting a voter’s identity to the vote itself.
Status: Conceptual · Proposed · Not validated
Important limitation
This page describes an exploratory system idea. It is not a legal proposal, an implemented election system, or a recommendation to replace Sweden’s current voting process.
Any real implementation would require extensive legal, democratic, cryptographic, security, accessibility, and independent review.
Core idea
The voter uses BankID once to verify identity and voting eligibility. After that check, the identity is separated from the voting process.
The voter receives a random, short-lived, single-use QR token that is used on a secured tablet at the polling station.
BankID → Eligibility check → Identity separation → Anonymous QR token → Polling tablet → Encrypted ballot box
BankID may confirm that a person is eligible to vote, but it must never be connectable to what that person votes for.
Election scope
A shared voting flow could potentially include:
The system would also need to handle blank votes, abstaining from one election, correcting a selection before submission, language support, accessibility tools, and voters who cannot use digital technology.
Identity separation
BankID could verify eligibility, district, election access, and whether the voter has already completed the process.
BankID must not sign the party choice, store the vote content, create a revealing receipt, or access the completed vote.
The identity layer knows who the voter is. The voting layer knows that the token is valid, but not who the voter is.
Voting process
Ballot secrecy
The following connections must not be recoverable:
Possible mechanisms could include blind signatures, anonymisation services, mix networks, homomorphic encryption, multi-party keys, and public verification without revealing individual votes.
Fallback and access
The system would need fallback procedures for network failure, BankID outages, broken tablets, overload, power loss, invalid tokens, interrupted sessions, and suspected manipulation.
Alternatives would also be required for voters without BankID, a smartphone, or the ability to use digital technology.
Accessibility could include larger text, high contrast, screen readers, multiple languages, simplified instructions, physical assistance, and accessible alternatives.
Risks and open questions
Can identity and vote really be separated so no actor can reconstruct the connection?
How can the public verify that the polling tablet does what the system claims?
How can voters be protected when digital systems may create new forms of proof or control?
How would recounting, fallback voting, recovery, and independent auditing work?
Prototype
An initial prototype should use fictional parties, test identities, test QR tokens, multiple tablets, a simulated electoral register, anonymisation, and an encrypted test ballot box.
Testing should include double voting, token reuse, interrupted sessions, network failure, manipulated tablets, invalid eligibility, old screenshots, and attempts to connect identity to a vote.
Any real political pilot would require independent security review, legal review, accessibility testing, cryptographic auditing, fallback voting, and documented recount procedures.
Current status
This is an exploratory concept, not an implemented or validated voting system. Its central research question is whether a digital system can verify that the correct vote was counted without proving how a specific person voted.