Independent concept · Digital voting

Digital voting with BankID, anonymous QR tokens, and polling-station tablets.

A concept for how municipal, regional, and parliamentary elections could potentially be conducted digitally at polling stations without connecting a voter’s identity to the vote itself.

Status: Conceptual · Proposed · Not validated

Important limitation

This is not a finished election system.

This page describes an exploratory system idea. It is not a legal proposal, an implemented election system, or a recommendation to replace Sweden’s current voting process.

Any real implementation would require extensive legal, democratic, cryptographic, security, accessibility, and independent review.

01

Core idea

BankID verifies eligibility. A QR token starts anonymous voting.

The voter uses BankID once to verify identity and voting eligibility. After that check, the identity is separated from the voting process.

The voter receives a random, short-lived, single-use QR token that is used on a secured tablet at the polling station.

Proposed flow

BankID → Eligibility check → Identity separation → Anonymous QR token → Polling tablet → Encrypted ballot box

BankID may confirm that a person is eligible to vote, but it must never be connectable to what that person votes for.

02

Election scope

One flow for three elections.

A shared voting flow could potentially include:

  • Municipal elections
  • Regional elections
  • Parliamentary elections

The system would also need to handle blank votes, abstaining from one election, correcting a selection before submission, language support, accessibility tools, and voters who cannot use digital technology.

03

Identity separation

The identity layer must not become the voting layer.

BankID could verify eligibility, district, election access, and whether the voter has already completed the process.

BankID must not sign the party choice, store the vote content, create a revealing receipt, or access the completed vote.

Separate layers

The identity layer knows who the voter is. The voting layer knows that the token is valid, but not who the voter is.

04

Voting process

From polling station to encrypted ballot.

  1. A polling worker starts a session on a locked polling tablet.
  2. The voter completes the BankID eligibility check.
  3. The identity is separated from the voting session.
  4. A cryptographically random single-use token is created.
  5. The QR token is scanned on the polling tablet.
  6. The voter selects the eligible elections.
  7. The voter reviews all selections before submission.
  8. The vote is encrypted and sent to the digital ballot box.
  9. The token is marked as used and local session data is removed.
05

Ballot secrecy

The system must not prove how someone voted.

The following connections must not be recoverable:

  • Personal identity and party choice
  • BankID identity and vote
  • QR token and vote in the same database
  • A receipt that reveals the selected party

Possible mechanisms could include blind signatures, anonymisation services, mix networks, homomorphic encryption, multi-party keys, and public verification without revealing individual votes.

06

Fallback and access

No voter should lose voting rights because of technology.

The system would need fallback procedures for network failure, BankID outages, broken tablets, overload, power loss, invalid tokens, interrupted sessions, and suspected manipulation.

Alternatives would also be required for voters without BankID, a smartphone, or the ability to use digital technology.

Accessibility could include larger text, high contrast, screen readers, multiple languages, simplified instructions, physical assistance, and accessible alternatives.

Risks and open questions

What must be solved before real-world use.

01

Ballot secrecy

Can identity and vote really be separated so no actor can reconstruct the connection?

02

Software trust

How can the public verify that the polling tablet does what the system claims?

03

Coercion and vote buying

How can voters be protected when digital systems may create new forms of proof or control?

04

Recount and recovery

How would recounting, fallback voting, recovery, and independent auditing work?

07

Prototype

Begin with a simulated election.

An initial prototype should use fictional parties, test identities, test QR tokens, multiple tablets, a simulated electoral register, anonymisation, and an encrypted test ballot box.

Testing should include double voting, token reuse, interrupted sessions, network failure, manipulated tablets, invalid eligibility, old screenshots, and attempts to connect identity to a vote.

Any real political pilot would require independent security review, legal review, accessibility testing, cryptographic auditing, fallback voting, and documented recount procedures.

Current status

Conceptual · Proposed · Experimental.

This is an exploratory concept, not an implemented or validated voting system. Its central research question is whether a digital system can verify that the correct vote was counted without proving how a specific person voted.

Sources and related work

Continue exploring.