How about your idea plus.
Tear off your tag.
Scan ballot into machine which spits the ballot back to you with a stamp “scanned” (which would prevent it from being scanned twice). The scanned ballot is for comparison to a receipt which shows how your votes were cast electronically. Compare the two. If recorded correctly, press “approve” and the never to be scanned again ballot goes into a locked, numbered box.
If the receipt doesn’t match the ballot, press “reject”, the un-readable ballot is shredded right there and you get to vote again.
.
Re Ballot security:
I like it!