Blind signatures for untraceable payments (1998) [pdf]
sceweb.sce.uhcl.edu
sceweb.sce.uhcl.edu
There are attempts to combine the decentralization of bitcoin with untraceability. Monero[1] is a working coin using ring signatures. Zerocash[2] is still being researched/developed.
It assumes the elector can recognize the quirks of the signature of the trustee, yet it also assumes that the trustee can not do this (for lack of having a copy of his signature). There are two simple attack vectors here:
1.) The trustee can see who is on the return envelope, and if it is the address of a person whose vote he wants to know he adds a quirk to his signature which he can later recognize. Thus the scheme fails.
2.) The trustee can make a carbon copy of his signing of the carbon-lined envelope. Thus he can identify every tiny quirk of every signature on every envelope. He also knows the return addresses, so he can link the return addresses to the votes.
Or did I miss something here? Or would the trustee in the digital version not be allowed to use different signatures? If not, how would an elector recognize his own ballot?
Patent-free now, btw. I still think a great Chaumian implementation will pwn all blockchain based systems.