Group signature schemes allow users to sign messages on behalf of a group while (1) maintaining
(within that group) with respect to an outside observer, yet (2) ensuring
of a signer (by the group manager) when needed. In this work we give the first construction of a group signature scheme based on lattices (more precisely, the
assumption), in the random oracle model. Towards our goal, we construct a new algorithm for sampling a basis for an orthogonal lattice, together with a trapdoor, that may be of independent interest.