From Ballot to Declaration
IEBC · KIEMS · RTS · PKI
PDF
Stage 1 of 10
Voter authentication
Stage 1 of 10: Voter authentication
Stage 1

Voter authentication

Biometric ID at the KIEMS kit

The voter presents their ID or passport. The Presiding Officer uses the KIEMS kit's biometric reader to verify the voter's fingerprint against the register before issuing ballot papers. This repeats for every voter, all day.

= eMudhra PKI checkpoint
Election-day secure transactions

Digital Certificates at the scale of a national election

Every secure transaction on polling day — voter authentication, on-device signing of Form 34A, mutual-TLS transmission to RTS, and results ingestion at national tallying — is anchored by a named digital certificate. Below is the certificate inventory required to cover the full IEBC operational footprint end-to-end.

Computed inventory
150,388
Sum of all named certificate buckets
Planned issuance
~200,000
Including operational buffers, rotation & re-issuance
Root of trust
1
Licensed E-CSP CA (eMudhra) — single trust chain
Device DSC
60,000
KIEMS Kits
Device DSC per polling-station kit
Device DSC
10,000
KIEMS Contingency
Ward-level backup kits, pre-provisioned
Personal DSC
60,000
Presiding Officers
Personal signing DSC — one per polling station
Personal DSC
290
Returning Officers
Constituency-level RO signing certificate
Personal DSC
47
County ROs
County Returning Officer signing certificate
Personal DSC
1
National RO
Chairperson — declares national result
API / Access DSC
50
Party Agents
Per-agent API client certificate for results feed
API / Access DSC
5,000
Miscellaneous
Observers, media, technical staff, auditors
Device DSC
15,000
Diaspora
Diaspora polling stations & consular officers

Kit provisioning & SD-card DSC profiling

Before any kit reaches a polling station

  1. Secure SD card manufactured
    Secure-element card with unique hardware serial
  2. Card serial registered
    Logged against IEBC asset register
  3. Officer biometric enrolment
    Captured during PO training / accreditation
  4. CA issues Device + Personal DSC
    Two certs per kit-officer pairing via CSR
  5. Certificates loaded onto card
    Private keys generated on-card, never leave secure element
  6. Card inserted into KIEMS kit
    Kit ↔ card ↔ officer triplet recorded
  7. Kit commissioned to station
    Polling-station ID bound into certificate metadata

Election-day signing & submission

The officer's day doesn't change — the crypto works underneath

  1. Voter authentication
    Fingerprint match on the register (EVID)
  2. Physical voting
    Manual, offline — KIEMS not involved
  3. Manual counting
    Counted by clerks, agents present
  4. Form 34A completed on paper
    Hand-transcribed and physically signed
  5. Officer fingerprint match
    Unlocks local signing on the card
  6. Personal DSC signs the form PKI
    Image + data hash signed on-device
  7. Transmission to RTS PKI
    Device DSC authenticates kit via mutual TLS
  8. Simultaneous tallying
    Constituency · county · national — at once
  9. Results declaration
    National centre publishes to public portal
Resilience

Edge cases, handled by design

KIEMS kit fails

Officer removes the SD card — certs and private keys travel with the card. A ward-level backup kit re-validates the chain; officer re-authenticates with the same fingerprint. Commissioning record updated with the new kit serial.

SD card lost or damaged

Treated as a revocation event, not a swap. Card certificates revoked at the CA; new card issued via expedited field revalidation using the officer's existing biometric enrolment. Rare edge-of-edge case.

Officer reassigned late

Biometric capture plus a CSR the CA signs within minutes. Certificate is loaded onto the card well within normal last-minute reassignment windows — an operational, not cryptographic, bottleneck.

Fingerprint unreadable

A PIN / passphrase serves as the secondary unlock factor — the same fallback pattern the EVID system already uses for voters. A genuinely unreadable print never blocks signing.

Connectivity loss

Signing is entirely local — fingerprint and certificate both live on the card, no live server needed. Connectivity is only required at RTS transmission, which already has satellite backup.

Cloned or spoofed kit

RTS validates every submission against the eMudhra-rooted trust chain via mutual TLS. A kit without a valid, registered device DSC cannot establish the connection — let alone submit results.

Every entry above resolves to the same single trust chain. One licensed root, hundreds of thousands of leaves — devices, officers, and agents — each individually accountable, revocable, and cryptographically verifiable from the polling station all the way to the National Tallying Centre.