The trick to the 3-ballot voting protocol is that not everyone can validate their vote. However, when a group of voters band together, they should be able to validate that a subset of their votes (1/3) were registered with high probability.
With a sufficiently large group of voters checking results, the law of large numbers comes into play and they can statistically detect the presence of voting fraud.
The desired outcome is to prove that each vote came from a valid voter, while being impossible to prove which vote came from whom.
The coercing party can insist that you take a mobile phone picture of your ballot. This kind of coercion is common in some regions of Russia where civil servants and teachers are told by their superiors that they must vote for the preferred party “or else”, and a mobile phone picture is demanded as proof.
Edit: Perhaps I wasn't clear. Each of the N ballots is already filled out for a different candidate. The envelopes are all identical and sealed by you inside the voting booth. That way an existence proof of a ballot for the given candidate leaks absolutely no information. There are no empty paper ballots, and none of the paper ballots can leave the polling station. Ballots need to be counted both from the "vote" and from the "discard" boxes. Ballots missing from the discard box prove vote tampering.
You go into the voting booth, seal the N ballots in the N identical envelopes, being sure to keep track of where the ballot for your desired candidate is. You leave the voting booth and drop the one envelope in the vote box, and the N-1 envelopes in the discard box.
Even if you're forced to videotape inside the voting booth of your sealing the N ballots in the N identical envelopes, you could pull a quick 3-card-monty when leaving the voting booth. Even a quick random shuffle would be sufficient to statistically nullify your vote, or if you're only able to keep track of where the Dr. Evil ballot is, a quick deal from the bottom of the deck would guarantee a vote for a random opposition candidate. As long as there's some spot between the polling both and the ballot boxes that isn't covered by video, there's no way for a third party to know which ballot went where.
You aren't allowed to leave the polling station with any of the envelopes, and a tally of the ballots in the discard box will show what percentage of people have left the polling station with their discarded ballots. Any non-negligible percentage of "discard" ballots leaving the polling station will make the whole vote suspect. (The discard ballot count will also provide circumstantial evidence for which way the tampering is going, although Dr. Evil will always claim it's false flag vote tampering to make him look bad).
If someone is really coerced in sneaking their discard ballots out of the polling station, they could sneak N-1 ballots out and either put the ballot for Dr. Evil in the discard box or burn it right outside the polling station. They then show the jackbooted thugs the other N-1 ballots. They end up not voting, but at least Dr. Evil is denied the vote.
This requires the poll workers to be somewhat impartial. If they are not all bets are off. In the German Democratic Republic voters where socially pressured (by official policy) to not use the booths at all.
(An exception is when you are a government delegate voting for chancellor, in which case you pay a fine of 1000€, especially after the president has clarified this rule to new delegates repeatedly)
The election council and a lot of privacy-conscious citizens weren't amused to say the least, but a subsequent ruling by a judge turned out that it isn't strictly speaking illegal, because the law doesn't explicitly prohibit photography in the ballot booth. So until parliament enacts a law that forbids it (like Germany), we are stuck with this rather dubious phenomenon.
At least we've banned voting computers for a good while — the ones we had ran closed source software and the votes cast couldn't be verified by the voters or the election council — so there's that.
That doesn't solve the potential problem of vote stuffing... Still thinking about that one.
Sounds like you might be on the right track if you can get over that hurdle somehow.
One approach to this problem is to make it easy to cancel a previous ballot and submit a new one, so you can get your evidence that you voted the way e.g. your employer wanted you to, but then you can cancel it and vote with your conscience.
That doesn't work if someone else has already told them the same ID.
r = f(k, p)
Suppose r may be 1 or 0. The meaning of 1/0 will be randomly distributed among the population, and will be made known to you when you place your vote, but at no other time. So, later on, you understand that a value of 1 means your vote counted for candidate A, but if someone tries to coerce you, you can realistically claim the opposite.
(That is, how do you prevent a butterfly-ballot-style situation where people think they're voting for Gore, accurately cast a ballot that appears to them to be a vote for Gore, and actually end up casting an objectively valid vote for Buchanan?)
1. Enter your vote and receive an identifier
2. Group n identifiers into a batch ensuring not all votes in the batch are for the same candidate. Record the n identifiers into a block then randomly order the identifiers but don’t record the randomized sort order. Display the index of their identifier to each user but don’t record it. Record the actual vote in this (random) order to the block. Allow each voter to see all votes recorded in the block at each location (including the one only they know represents their vote). Allow the voter to manually tally the block to ensure the sum of symbols reflects their vote intent. Present to each voter cryptographic proof of the existence of the block and the net affect the block as a whole has on the vote tally for each candidate.
Each voter leaves with:
1. cryptographic proof of having voted
2. Cryptographic verification of the effect their vote had on vote tally
3. Ability to claim having voted for any candidate represented in their voting block/inability to prove to others who they voted for while being sure of how their vote was counted themselves.
As I remember, it's still an open problem to set things up (without requiring trusted hardware or trusting the government to destroy a private homomorphic encryption key) so that I can't later prove to Dr. Evil's jackbooted thugs that I voted for Dr. Evil.
Though, maybe there's some mechanism where I actually generate ballots for all candidates and only submit one of the ballots and it's impossible for me to prove which one I actually submitted, and I could cheat by submitting more than one ballot but there's a zero-knowledge proof that my ballots were for all of the N candidates, so in an American-style first-past-the-post voting system, submitting all of my ballots has the same effect as submitting none of my ballots.
Every voter is issued one "vote coin" at registration time. There are special addresses for each candidate. Each voter sends their "vote coin" using a zero-knowledge/private transaction to the candidate of their choice. It's totally auditable, not possible to vote more than once, etc.
The main issue is in making it potentially easy to sell your vote, which as the OP was getting at is at the heart of the tension.
"Plutocracy".
http://www.slate.com/articles/news_and_politics/net_election...
I don't see much problem in selling your vote if there's no way to verify that you're not ripping off the person buying the vote.
Now you can take as many pictures you like of whatever ballot which proves nothing.
Though, I don't understand the purpose of the pen in the proposal. There's already one of every possible ballot, so you don't use the pen to mark candidates. You don't write your name on the ballot, as that would ruin anonymity. You don't cross-out the ballots that you don't cast, as that would open back up the weakness to photography. So, how is the pen used?
Also, what's the purpose of having the official put the ballot in the box instead of having the voter put the ballot in the box? Is it to prevent multiple votes from being cast? You need to have a discard box for the unused ballots and tally those discarded ballots in order to detect when the jackbooted thugs force people to walk out of the polls with their discarded ballots in order to prove how they didn't vote. Once you have this, you've also got multi-vote detection.
And since it's a public blockchain, you know exactly which token went to whom.
You don't (well, shouldn't) know with Z-Cash/Zerocoin