Skip to content

feat: count approval votes while they stay encrypted - #10

Merged
renezander030 merged 2 commits into
masterfrom
feat/fhe-private-approval-tally
Sep 6, 2026
Merged

renezander030 merged 2 commits into
masterfrom
feat/fhe-private-approval-tally

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Outcome

Draftcat can now combine three or more approval votes while the tally collector sees ciphertext rather than each reviewer's approve or reject choice.

The README leads with the non-technical value, a copy/paste three-reviewer example, and clear "Use it when / Skip it when" guidance. The existing zero-knowledge receipt remains the right feature for sharing a compact approval proof; this PR adds the separate job ZK does not do: computation over hidden inputs.

What changed

  • add draftcat fhe-vote keygen|encrypt|tally|decrypt
  • encrypt one vote plus a contribution counter with Lattigo BGV
  • add ciphertexts without a decryption key and decrypt only the aggregate
  • bind inputs to key/context commitments and reject wrong-key, wrong-context, duplicate, malformed, small-group, and count-mismatched input
  • require an exact expected group size before reporting quorum
  • protect default secret filenames through .gitignore and mode 0600
  • document a buyer/supplier/auditor quorum walkthrough and the complete threat boundary

Honest boundary

This is an experimental, shallow encrypted-addition preview—not an audited voting protocol or arbitrary-depth FHE engine. It provides confidentiality from a separate collector, not contributor authentication or a range proof. Ciphertext files (about 176 KB each in the local check) are still sent. Keep the collector away from the secret key and give the key owner only the final tally.

Verification

  • go test ./...
  • go vet ./...
  • go test -race ./internal/fhevote
  • CLI journey: approve/reject/approve -> QUORUM MET: 2 of 3
  • plaintext scan found no context, invitation, approve, or reject value in ballot/tally JSON
  • negative coverage includes wrong key/context, duplicate ballot, fewer than 3 ballots, malformed ciphertext, edited count metadata, unknown JSON fields, and partial expected group

Review focus

  1. Is the cross-organization private quorum use case valuable enough to keep?
  2. Is the collector/key-owner separation practical for Draftcat users?
  3. If approved and merged, add FHE/homomorphic-encryption GitHub topics without removing higher-value discovery topics.

@renezander030
renezander030 merged commit 3fca323 into master Sep 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant