vSPACE: Voting in a Scalable, Privacy-Aware and Confidential Election
摘要
The vSPACE experimental proof-of-concept (PoC) on a TrueElect extended protocol presents a novel approach to secure, private, and scalable elections, extending the TrueElect and other related protocols with the integration of Self-Sovereign Identity (SSI) enabled Privacy-Enhancing Technologies (PETs). Zero-Trust Architecture (ZTA) principles and practices were used for a split-trust design to minimize human errors or attacks, along with using a trustworthy Infrastructure as Code (IaC) automation for staging a perfectly democratized e-governance polling; while also leveraging confidential computing, continuous authentication, multi-party computation (MPC), and Well-Architected Framework principles to address cybersecurity and privacy protection challenges. Moreover, vSPACE integrates Distributed Ledger Technology (DLT) for immutable and certifiable audit trails, and employs Kubernetes confidential clusters as ZTA spokes for hosting decentralized applications (dapps) with a connectivity hub of an nTier-based Enterprise-Scale Landing Zone (ESLZ). The IaC model ensures rapid deployment, consistent management, and adherence to security standards, making vSPACE a future-proof solution for digital voting systems. Our poster and concept note include motivations behind low-level design choices, ZTA specifications with a threat modeling assurance review, quantitative metrics on efficiency performance, and preliminary implementation IaC tooling.