Abstract:Serving as a pivotal privacy preserving technology, group signatures provide robust anonymity assurances to users. However, general group signature schemes often rely on group managers who can open the identities of signers, a feature that conflicts with the decentralized property of blockchain and falls short of meeting stringent privacy requirements in certain applications. To address these limitations, we draw inspiration from double-authentic preventing signatures, group signatures with user-controlled linkability and group signatures with verifier local revocation signatures to propose a novel group signature scheme with user-controlled linkability and verifier revocation. This new scheme strikes an optimal balance between user privacy and platform management, providing a concrete instantiation based on lattices. We conduct security analysis under the random oracle model, which confirms that the proposed scheme satisfies selfless anonymity, traceability, and non-frameability. Performance evaluations indicate that the time costs and communication costs of our scheme are within an acceptable range, ensuring potential usage. Furthermore, we design a post-quantum secure medical data sharing system which integrates this advanced group signature scheme with blockchain technology.