Suppose thatf : {0, 1}m Æ {0 1}m is a preimage resistant
bijection. Define h : {0, 1}2m Æ {0, 1}m as follows. Given x OE {0, 1}2m, write x = x’ || x’’
where x’, x’’ OE {0, 1}m. Then define
†h(x) = f (x'!x''). where is “XOR” operationProve that h is not second
preimage resistant.
