opening. It is intended to weaken the high trust placed on the opener; ie, no anonymity
against the opener is provided by an ordinary group signature scheme. In a group signature
scheme with message‐dependent opening (GS‐MDO), in addition to the opener, we set up
an admitter that is not able to extract any user's identity but admits the opener to open
signatures by specifying messages where signatures on the specified messages will be …