Preference
Ranked Voting

PRV is designed to make ranked voting tractable across millions of voters and thousands of candidates, while reducing ballot exhaustion, arbitrary tie resolution and opportunities for adversarial intervention.

The intended outcome is the candidate most likely to provide broad public utility given incomplete expressed preferences. A deterministic counting rule and an anonymous authorization protocol address different parts of that objective: how preferences become a result, and how one eligible participant contributes one accepted ballot.

Concept PRV terminal with a searchable field of 1,000 candidates, a three-candidate ranking, tactile controls and a separate authorization appliance.
Terminal concept. Search and ranking remain manageable as the registered field grows; explicit selections are reviewed before printing. This rendering depicts proposed equipment.

Eligibility without an identity-bearing ballot

The central security proposition is a separation of authority. The state establishes eligibility and limits issuance. A blind-issued credential carries that entitlement into the polling place. An isolated authenticator converts it into a one-use ballot authorization. The deposited ballot carries evidence of authorization, while the voter retains a detached verification receipt.

This confines the Sybil boundary—the decision that one eligible person receives one entitlement—to the issuance domain. Identity need not accompany the entitlement into the count. Cryptographic uniqueness then concerns repeated consumption of the same entitlement, rather than repeated disclosure of the person.

  1. 01 / ISSUANCE

    Identity → credential

    The registry knows eligibility and issuance status. Blinding hides the credential secret.

    identity → issued(E)
  2. 02 / AUTHORIZATION

    Credential → permit

    The air-gapped authenticator verifies entitlement and reserves its reuse marker.

    credential → N, permit
  3. 03 / CASTING

    Permit → ballot

    A signed acceptance record binds the permit to exactly one encrypted ballot record.

    N + ballot → accepted
  4. 04 / VERIFICATION

    Receipt → evidence

    A private receipt locates the committed record and its inclusion evidence.

    receipt → record proof

The PRV 1.0 package specifies the count. The credential, paper and receipt architecture developed here is a proposed extension, not an implemented or proven election protocol. Blind issuance can hide the identity-to-credential link; it cannot establish that a registry contains only eligible people or prevent its issuer from granting unauthorized credentials.

A ballot with a detachable witness

At home, the voter authenticates to request an election chit. At the polling place, the chit is consumed for authorization. After checking the paper ranking and the machine’s committed record, the voter tears off the receipt and deposits the stamped ballot. The scanner then supplies a signed acceptance confirmation for the retained strip.

Concept paper ballot with readable candidate ranks and an authorization stamp; a receipt has been torn from its perforated edge and retains a separate complete barcode without candidate selections.
Paper concept. The receipt and retained ballot each have a complete machine-readable code. The perforation separates the documents, not the pixels of a single barcode. The printed codes are illustrative.

The retained ballot

Contains the human-readable explicit ranking, election and ballot-style identifiers, a one-use authorization stamp, and the binding to its encrypted record. It carries no name, government identifier, original chit secret or identity-linked issuance serial. Readable paper is preserved under election custody for reconciliation and an independently specified audit.

The detached receipt

Contains a fresh secret lookup value, the committed-record digest and the device’s signed acknowledgement. It contains no candidate selections or decryption material. The receipt can demonstrate inclusion of the committed record; it must not become a transferable proof of a particular cast ranking.

For a hand-marked ballot, a pre-cast scanner first reads the marks, displays its interpretation and commits to that encoding while returning the paper for review. Ambiguous marks require correction before commitment. The voter may challenge and spoil this committed test record, or detach the strip and cast the reviewed paper. Machine-readable selections must agree with the readable ranking; a barcode is never a substitute for that check.

A tear is an observable custody action. It does not make a photocopiable barcode uncopyable. Authentication, replay rejection and record binding must remain valid even if every piece of paper has been copied. A receipt also gives evidence of a missing record only if its acknowledgement is signed and there is a defined publication deadline and dispute procedure.

Credential and authorization protocol

Let E identify the election and its fixed rules, D the assigned offline acceptance domain, and x a high-entropy secret generated by the voter’s trusted client. The issuer certifies (E, D, x) through blind issuance, with E and D enforced as common attributes or by a published key assigned to that context.

  1. Issue once after an eligibility check

    The registry authenticates the person and atomically records that the election entitlement has been issued. The client blinds its request, receives the issuer’s signature, unblinds it and verifies it before printing the chit. Independently witnessed issuance totals and confidential roll audits are needed to constrain overissuance; threshold signing can distribute that authority. The issuer must not choose or retain x, embed a citizen-specific tag, or supply a different signing key to each voter. Published common keys and an independently verifiable client are necessary to resist issuer tagging.

    Blind signatures separate authorization from the signed message; RFC 9474 specifies one blind-signature primitive. That RFC alone does not supply the anonymous-credential proof, nullifier relation or complete election construction required here.

  2. Derive a stable, non-reversible reuse marker

    The same valid credential must always produce the same election-specific nullifier N. Its uniqueness derives from the credential secret, not the potentially randomized signature. The hash is domain-separated, and every tuple uses an unambiguous canonical encoding.

    N = H("PRV / nullifier / v1", E, D, x)

    Reusing a chit reproduces N; producing a new receipt does not change it. A uniformly random 256-bit x makes inversion computationally infeasible under the hash assumption. Hashing a name, identity number or predictable state-assigned serial would not provide that protection. The election context also prevents this marker becoming a cross-election identifier.

  3. Prove entitlement without publishing the chit

    The public acceptance record needs a zero-knowledge proof that the nullifier belongs to an authentic credential. Merely trusting the authenticator’s stamp would let a compromised authenticator mint apparently valid votes. The intended proof relation is:

    πelig = ZKPoK { x, σ :
    Verifyissuer(σ; E, D, x) = true
    ∧ N = H("PRV / nullifier / v1", E, D, x) }

    The credential suite must implement this relation with blindness, unforgeability, knowledge soundness and zero knowledge under stated assumptions. The proof must be bound to the election manifest and protocol version. Selecting and proving a concrete suite, its encoding and its setup remains required work; a diagram of this relation is not a cryptographic implementation.

  4. Reserve authorization at the isolated appliance

    The authenticator checks the credential, context and spent-state journal, then atomically reserves N and signs a permit containing E, D, N and a fresh permit identifier. It has no need for a citizen identity or the ranking. The ballot station accepts only an authorized permit for its assigned domain. The authenticator necessarily processes the presented chit in this version; it must not retain the secret, log identity-correlated observations or share a camera timeline with registration.

  5. Bind acceptance to the actual ballot

    The voting station commits to the encrypted explicit ranking C, a proof that its encoding is valid, the receipt lookup tag and the permit. The scanner verifies the entitlement proof, atomically moves the nullifier from reserved to cast, and signs this complete record with an explicit cast status. It prints that acceptance acknowledgement onto the retained strip or a small confirmation slip after deposit. A signed pre-cast commitment certifies preparation only, not acceptance. The reader must not leave with only a prepared acknowledgement when acceptance has failed. A copied stamp attached to a different ciphertext must fail the binding check. Images, handwritten stamps and barcode checksums do not authenticate these fields. A printed code may carry a record locator and digest rather than every proof byte, but the complete authenticated record must be available to the offline verifier before acceptance.

Anonymous chits are bearer credentials. Theft, voluntary transfer, a compromised home client and coerced handover remain possible without additional safeguards. Lost-chit replacement and revocation must preserve the single-entitlement invariant; an issuer that cannot see the original secret cannot simply locate its nullifier. Those procedures must be specified before use.

Offline uniqueness requires an acceptance boundary

Two disconnected machines cannot know immediately that the same copied token was accepted by the other. A stable nullifier makes the collision recognizable once their records are compared; it does not transmit the comparison.

DeploymentUniqueness behaviorOperational consequence
Assigned offline authorityThe credential is restricted to one acceptance domain with one authoritative, durable nullifier journal. Other domains reject it.Within that authority, reservation and casting are atomic and replay is rejected immediately. Redundant devices require serialized access or exclusive, auditable failover.
Independent offline machinesEach can reject its own repeats. Cross-machine repeats become visible only during signed-log reconciliation.Acceptance is provisional. Reconcile before certification and adjudicate collisions under a published rule; a first-arrival rule could reward a thief.

State progresses through unseen → reserved → cast, with signed records for spoiled or cancelled permits. A challenge or printer failure must not permanently consume the vote: a replacement uses the same nullifier after the prior permit is demonstrably void. Power-loss recovery, rollback resistance and poll-worker recovery actions belong to the protocol, not to an informal exception.

What the receipt can certify

Generate a fresh receipt secret r, independently of both the identity and the credential. Put only its lookup tag t in the election record. Commit to the complete encrypted ballot envelope and its authorization; put its digest q on the detachable strip. After deposit, complete that receipt with the scanner’s signed cast acknowledgement. Include protocol version, election context and status in every signed message.

t = H("PRV / receipt / v1", E, r)
q = H("PRV / record / v1", E, D, N, C, πelig, πballot, permit, t)
receipt = (E, r, q, Signscanner("PRV / cast / v1", E, q))

At home, a verifier computes t locally, retrieves the corresponding encrypted envelope and verifies its digest, signatures and inclusion proof against a signed election checkpoint. Independently mirrored checkpoints and consistency proofs are needed to detect a bulletin board that shows different histories to different readers. The receipt secret need not be uploaded. Anonymous or local lookup avoids adding a new identity trail through account logins, network addresses or query logs.

The ballot encryption must be randomized and threshold-protected under published trustee keys. A plain hash of a short ranking is vulnerable to enumeration and is not ballot secrecy. A well-formedness proof must establish, without revealing the selections, that the ciphertext contains a nonempty strict ranking over the fixed candidate manifest:

πballot = ZKPoK { B, ρ : C = Enctrustees(B; ρ)
∧ 1 ≤ |B| ≤ m ∧ no repeated candidate in B
∧ every candidate in B belongs to the committed election manifest }

Here B is the explicit ballot and ρ the encryption randomness. Bind the proof to the election context and protocol version. Neither the decryption key nor ρ belongs on a cast receipt. Threshold key generation, trustee failure recovery and verifiable computation over these ciphertexts require a specified protocol and independent review.

Recorded as cast

The receipt matches one accepted encrypted envelope. Its digest and inclusion evidence detect omission or substitution relative to that commitment.

Cast as intended

The paper ranking must match the voter’s review. A pre-cast challenge mechanism can open an already committed test ballot, which is then spoiled and never counted. Repeated successful challenges provide statistical evidence about the devices; a receipt by itself does not prove correct encryption of its cast ballot.

Tallied as recorded

The accepted encrypted records must feed a verifiable computation of PRV. An independently checked tally proof and the paper audit establish more than a green “found” indicator on a website.

These are the separate verification obligations illustrated by ElectionGuard’s verifiability model and its cast-or-challenge process. ElectionGuard is a reference for those mechanisms; it is not a ready-made implementation of PRV’s recursive count.

The deposited paper has no direct identity field, but distinctive handwriting, physical custody, timing and a recognizable ranking can still identify its author. A take-home key that reveals the exact cast choices would also enable vote selling or coercion. The target is verification without transferable evidence of those choices, and that stronger receipt-freeness property remains to be proved for the complete protocol.

Receipt and replay demonstrator

Generate a synthetic chit, stamp a record, then detach the receipt. Test repeated use and record substitution. SHA-256 and local digital signatures run in this browser.

This instrument demonstrates identifier separation and record checks only. It uses placeholder ballot bytes and a local signing key; it does not implement blind issuance, eligibility verification, zero-knowledge proofs, encryption or an election bulletin board. Reloading clears the session.

Private chit

Secret x stays out of the public record.

Not issued

Deposited record

Nullifier N exposes reuse; tag t locates the record.

No accepted record

Detached receipt

Secret r and signed digest q travel home.

Not detached

No credential issued. Begin with a synthetic entitlement.

Deterministic preference completion

For a finite candidate set C with m candidates and a multiset of n > m valid ballots, PRV preserves each submitted strict ranking and appends inferred ranks. Omission is an unexpressed preference, not an explicit rejection. Inferred positions have operative voting force and can change the winner.

  1. Select the nearest informative donor class

    Match the longest prefix of the target as an ordered subsequence of each other current ballot. Among equal prefix lengths, select the lexicographically earliest position vector. Retain only donors containing an active candidate absent from the target. This is a precisely defined equivalence class, not an informal demographic similarity measure.

  2. Append one candidate and preserve the explicit order

    Delete the target’s existing candidates from each selected donor. The modal first residual candidate becomes the next inferred rank. Resolve a modal tie with residual positional support vectors; an unresolved perfect tie returns a failure code. Expansion processes the greatest incomplete length and shared-support priority first, committing equal-priority batches simultaneously from an unchanged snapshot.

  3. Eliminate from completed active permutations

    A candidate with more than half the active first preferences wins. Otherwise remove the unique lexicographic minimum of the full positional-support vector and repeat. Exact unresolved elimination or final ties, missing evidence and the specified symmetric cycle return explicit failures. Successful completion prevents ballot exhaustion; it does not guarantee an election will produce a winner.

SUBMITTED TARGETA → B
NEAREST DONORS3 × A → B → C → D
2 × A → B → D → C
COMPLETED TARGETA → B → C → D
Three immediate proposals for C outweigh two for D. Bold positions are inferred; A and B retain their submitted order. Every donor decision belongs in the audit record.

A bounded active field

Above the default threshold of 30 candidates, PRV seeds a fixed-offset bracket ladder from explicit rankings. The seed score is S(c) = Σ Nr(c) / 2r−1, evaluated exactly. Inferred ranks do not determine the initial seeding.

1,000candidates in the illustrative global field
10maximum active candidates per default mini-election
112fixed seed segments at nine new candidates per level

Process the lowest segment first and promote its winner into the next nine-candidate segment. With 1,000 candidates, the one-candidate bottom segment promotes automatically; 111 contested mini-elections remain. Every level projects the original submitted ballots afresh. An empty projection still participates and is completed within that active field.

lowest seed segment→ winner + next 9→ winner + next 9→ final active field

This bounds the active candidate dimension, not total running time. Millions of ballots still require efficient pattern grouping, exact multiplicity handling and independently checked parallel or distributed execution. The browser reference scans donor populations directly and is not an election-scale implementation. No million-voter throughput or utility-optimality result is established by this page.

Reference count demonstrator

Enter a strict ranking on each line, using > between candidate identifiers. The browser runs the existing PRV counting implementation; it does not implement the eligibility protocol.

Ballots after completion

    Count

      Outcome quality and adversarial evaluation

      “Most useful” needs a declared model of public utility and uncertainty. Ordinal ballots alone do not identify interpersonal utility magnitudes. PRV is a specified heuristic for completing and counting preferences; it does not directly solve a posterior expected-utility optimization. Testing the design objective requires measuring welfare regret, sensitivity to missing preferences and attack cost under explicit population models.

      Attack or failure modeRequired evaluation
      Donor poisoningMeasure how many genuine coordinated ballots change an inference, a winner or a failure. The reference counterexample flips 100 completions with two added donor ballots; one added ballot creates a perfect tie.
      Strategic ranking and truncationTest compromise, burial and omitted lower ranks. The draft contains failures of strategy-proofness, monotonicity, participation and later-no-harm.
      Nomination and seedingMeasure candidate additions, removals, clones and changes around bracket boundaries. Fixed brackets limit active size but introduce path dependence.
      Unrepresentative donorsVary correlated missingness and rare preference patterns. One very close donor can outrank a much larger but more distant group.
      Outcome reliabilityCompare against declared alternative rules on identical populations and information budgets. Report regret distributions, failure frequency, margins and uncertainty, not only average winner agreement.

      Credential security removes unauthorized ballot multiplication only under its issuance assumptions. It does not remove coordinated behavior by eligible voters. The existing PRV draft is also not Condorcet-consistent: a candidate who defeats every rival pairwise can be eliminated for insufficient first-place support. These are properties of the selection rule and require direct evaluation.

      Inspection, secrecy and an independently verifiable count

      An authenticator should expose its hardware design, source, reproducible build, boot measurement, key-loading ceremony, test vectors, signed state transitions and controlled data-transfer procedure to independent inspection. Those artifacts can establish specific evidence about a device; an air gap and published code cannot prove an arbitrary physical computer secure. Compromised firmware, supply chains, peripherals, randomness, removable media and human procedures remain within the threat model.

      Assurance should therefore include software-independent evidence. Voters inspect readable paper; custody records reconcile paper counts with accepted authorizations; an independently specified audit checks the outcome. The EAC’s software-independence and E2E evaluation framework provides a relevant standard of evidence. It does not certify this proposal.

      PRV introduces a further privacy requirement: publishing complete anonymous rankings can expose a distinctive voting pattern. That channel is documented in research on coercion-resistant ranked-vote tallying. Removing names or shuffling ballots alone does not close it. Public donor traces must not recreate a link from a receipt, nullifier or rare preference sequence to a person.

      A stronger target is threshold-protected computation over the committed explicit ballots, with a verifiable proof of the PRV execution and a carefully bounded public transcript. This requires a concrete privacy-preserving realization of recursive completion and elimination. A generic encrypted sum cannot compute that rule. A mixnet that simply releases every full plaintext ranking also leaves the pattern channel open. Proof size, computation cost and a paper-audit method for the complete PRV rule remain research obligations.

      The protocol’s testable claim is narrower and more useful than absolute security: eligible issuance can be separated from ballot identity; repeated credential use can expose a stable nullifier; a detached receipt can bind its holder to inclusion evidence without printing the selected candidates. A deployment must demonstrate those properties together, under explicit adversaries and failure procedures, before extending the claim to an election outcome.

      Specification and references

      The PRV count follows the 4 August 2026 deterministic draft and its executable Python reference. Its companion fixtures specify adversarial counterexamples, exact tie handling and bracket behavior. The anonymous credential and detachable-receipt extension above is separate from that package.

      1. PRV specification, Python reference and reproducibility fixtures
      2. RFC 9474 — RSA Blind Signatures
      3. ElectionGuard — cryptographic specifications
      4. Teague, Ramchen and Naish — Coercion-Resistant Tallying for STV Voting
      5. U.S. Election Assistance Commission — E2E Protocol Evaluation Process