Abstract:As a privacy-preserving authentication technique, ring signatures preserve user anonymity while ensuring message authenticity and integrity. They are widely used in scenarios such as electronic voting and blockchain transactions. To prevent malicious users from abusing anonymity and engaging in dishonest behavior, existing ring signature schemes employ a tracing authority (or regulatory authority) to reveal the real identities of any user. However, introducing such an authority may lead to privacy leakage for honest users, disrupting the balance between anonymity and traceability. To address these issues and promote the application and development of domestic cryptographic technologies, this study proposes an SM2-based ring signature scheme with traceability for illegal messages. The proposed scheme designs a tracing mechanism for a single illegal message, under which the tracing authority is permitted to reveal only the real identities of malicious users who publish illegal messages, while honest users remain anonymous, thus balancing anonymity and traceability. On this basis, this study further extends the proposed scheme by combining polynomial techniques with Merkle hash tree techniques. As a result, traceability for an arbitrary number of illegal messages is achieved, the scope of supervision over malicious users is expanded, and user verification overhead and communication costs are reduced. Security analysis demonstrates that the proposed scheme achieves unforgeability, anonymity, and traceability. Performance analysis indicates that the proposed scheme offers superior efficiency and practicality compared with existing ring signature schemes.