Framework and Implementation Plan for the U.S. Federal Election Electronic Voting System
Based on the Tri-Power Separation Principle of Registration — Transmission — Computation
Author: Bob Li
I. General Principles
This proposal puts forward a framework for an electronic voting system for U.S. federal elections. The core concept is to establish a tri-power separation architecture comprising Registration, Transmission, and Computation, designed to achieve three fundamental objectives:
● Fairness: Ensuring that the voting process and vote-counting results are open, equitable, and verifiable.
● Security: Effectively resisting cyberattacks through a distributed and independent server architecture.
● Usability: Providing voters with a simple, efficient experience compatible with both in-person and remote voting.
This is one of the currently known institutional frameworks capable of simultaneously satisfying all three requirements of computational fairness, individual verifiability, and attack resistance — with the distinctive advantage of being understandable and independently verifiable by the general public without any knowledge of advanced cryptography.
II. Why Electronic Voting?
Many people instinctively reject "electronic voting" as "insecure" or "unfair." In fact, this is a misconception:
● Reducing human error: Electronic voting minimizes mistakes inherent in manual vote-counting.
● Narrowing opportunities for manipulation: Fewer intermediary steps between casting and counting reduce the scope for human interference.
● Traceable evidence: All voting data and activity records are logged, making both lawful and unlawful conduct fully traceable.
In short, electronic voting is not only more efficient — it is more verifiable.
III. Security and Anti-Fraud Mechanisms
1. Protection Against Cyberattacks
● Municipal government servers are separated from the federal electronic voting servers.
● Hackers would need to simultaneously breach multiple layers of servers, making attacks extremely difficult.
● Every intrusion attempt is logged, leaving forensic evidence.
● The U.S. Congress could enact specific criminal legislation imposing severe penalties on hackers who interfere with elections.
[Core Security Argument: Decentralization as Defense]
The United States has thousands of municipal governments. Registration servers are independently deployed in a hidden, distributed manner, potentially numbering in the tens of thousands, spread across different states, local governments controlled by different political parties, and different IT management teams. Any attacker attempting to compromise the secrecy of an election would need to simultaneously breach or collude with every one of these tens of thousands of independently operated registration and transmission servers — a task that is impossible to accomplish both technically and in terms of real-world political feasibility. The security of the system does not rely on the integrity of any single institution, but on decentralization itself.
2. Prevention of Candidate Fraud
● All candidates, media organizations, and research institutions retrieve identical voting data from the same API.
● Each party can independently compute and cross-verify results.
● Transparent data flows reduce the possibility of single-point manipulation.
IV. The Tri-Power Separation Institutional Architecture
1. Municipal Government Website: Registration Authority
● Reviews and registers voters' basic information: name, gender, date of birth, security questions, email address, etc.
● Publishes the total number of residents in the jurisdiction, the number of registered voters, and the estimated number of in-person and mail-in voters.
● All registration information is stored exclusively on municipal government servers and is never uploaded to the electronic voting system.
2. STP.vote Electronic Voting Website: Transmission Authority
● Responsible for issuing Voting Passes.
● Provides API interfaces to transmit voting information in real time to the servers of all parties.
● Does not store or compute any voting results — its sole function is data relay.
3. Candidate and Independent Institution Servers: Computation Authority
● Each candidate, media outlet, and research institution independently establishes its own server.
● Receives voting data in real time via API.
● Independently tallies ballots and cross-verifies with other parties to prevent any single party from manipulating results.
[Tri-Power Information Isolation Table]
The table below clearly presents the information boundaries of each of the three subsystems, explaining why no single party can ever simultaneously know "who this person voted for":
|
Information Type |
Registration Server (Municipal Gov't) |
Transmission Server (STP.vote) |
Computation Server (Candidates) |
|
Knows voter's real identity |
✅ Yes |
❌ No |
❌ No |
|
Knows voting choice |
❌ No |
⚡ Handles during transmission; does not retain |
✅ Yes (anonymous) |
|
Knows random verification code |
❌ No |
✅ Yes |
✅ Yes |
|
Can link identity to voting choice |
❌ Cannot |
❌ Cannot |
❌ Cannot |
Conclusion: Only by simultaneously breaching both the registration server (which knows identity) and the transmission server (which knows the verification code binding) can an attacker link a voter's identity to their choice — and doing so would require simultaneously compromising tens of thousands of independently operated municipal registration servers across the United States, which is impossible in practice.
V. Voting Process Design
(1) Registration Stage
● Municipal governments obtain the district code and Voting Identification Code from the electronic voting website via API.
● A Voting Pass is generated; the QR code contains the district code, name, date of birth, and other information.
● The Voting Pass can be printed on paper or backed up via email.
● Voters' personal data is stored only on municipal government servers; the electronic voting website stores only the district code, Voting Identification Code, and date of birth (DOB) — all anonymous information.
(2) In-Person Voting Stage
● On Election Day, voters bring their Voting Pass to the polling station.
● Scan the QR code → enter name completion and date of birth → verification passed.
● Enter the unified federal voting page, select all choices, then click "VOTING".
● Voting data is automatically: transmitted in real time to the API-connected servers; printed as a paper receipt for the voter to sign; and emailed to the voter.
● The signed paper receipt is attached to the Voting Pass and deposited in the ballot box.
● Indelible ink is applied at the exit to prevent double voting; it remains effective for 24 hours.
(3) Mail-In Voting
● Available to military personnel, overseas voters, persons with disabilities, and other special groups.
● Apply for a Voting Pass on the municipal government website; upon identity verification, the pass is sent by email.
● Click the voting link in the email and complete the online vote; print the voting result and sign it; mail the signed ballot to the local polling station.
● Voting data is transmitted instantly; the paper ballot serves as a backup for verification.
(4) Random Verification Code Mechanism
● A random verification code is generated instantly by the STP.vote transmission website upon completion of each vote, and is bound to the Voting Pass used in that vote.
● The verification code is stored only on the STP.vote transmission server and the computation servers of all candidates. The municipal government registration server plays no role in generating or storing the verification code, thereby ensuring structural isolation between identity information and voting choices.
● Voters may enter their verification code on any candidate's computation server to confirm that their ballot has been accurately recorded. Since the verification code is completely detached from the voter's real identity, the verification process does not expose any personal information.
● Both the Voting Pass and the voting link are single-use only, preventing duplicate voting.
VI. Institutional Advantages
● Secure: Multi-layered protection combined with a distributed architecture; tens of thousands of independent registration servers make collusion attacks impossible in practice.
● Transparent: All data can be independently verified by multiple parties; candidates serve as mutual checks on one another.
● Efficient: Instant transmission and tallying, reducing manual steps.
● Traceable: Every stage of voting, counting, and auditing is fully logged.
● Highly compatible: Supports parallel operation of in-person voting and mail-in voting.
● No advanced cryptography required: The general public can understand and independently verify the entire system without any knowledge of cryptography.
VII. Conclusion
Without fair elections, there can be no true democracy.
Through an electronic voting architecture based on the tri-power separation of Registration — Transmission — Computation, the United States can achieve a federal election that is secure, fair, and transparent, while at the same time efficient and cost-effective.
This research was independently conducted by inventor Bob Li
Patent Application: 2022201573
Contact Information:
Email: bobli@stp.vote
WhatsApp: +61 420 355 918
X: https://x.com/STPvoteOfficial
Official Websites (under construction): STP.vote | STPvote.org | STPvote.com
Monday, November 9, 2020
Comments
Post a Comment