Currently, existing group signature schemes with user-controlled and sequential linkability (GS-UCSL) suffer from critical limitations: they lack post-quantum security, cannot efficiently revoke malicious signers, grant excessive tracing power to group managers (GM), and rely on heavy revocation lists or secure channels that incur high computation or communication overhead. To address these issues, we propose an efficient lattice-based conditional privacy-preserving GS-UCSL (LCGS-UCSL). Our scheme is built on lattice cryptography to achieve post-quantum security, and unifies implicit linkability, explicit linkability, and sequential linkability under user autonomous control. We design a polynomial-based revocation mechanism that eliminates revocation list verification and secure-channel token updates, enabling lightweight and privacy-preserving member revocation. To curb GM’s overreach, we introduce key-oblivious encryption to split users into traceable and non-traceable types without their awareness, and use cuckoo hashing to realize O(1) registry operations. We further integrate signature aggregation and non-interactive zero-knowledge proofs of knowledge to optimize batch verification and reduce communication overhead. We formally prove the scheme’s anonymity, traceability, Existential Unforgeability under Chosen-Message Attack, and non-frameability in the random oracle model, and validate its practicality via performance analysis. The results show that LCGS-UCSL achieves comprehensive functionality with competitive efficiency, filling the gap toward post-quantum secure GS-UCSL with efficient revocation and balanced privacy.
更多
查看译文
关键词
Group signature,User-controlled,Sequential linkability,Lattice,Aggregate,Revocable