Research Article
Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function
Table 4
Known-key distinguishing and
-word partial-collision attacks on 4-branch GFN-2.
| L | R | KKD | | Comp. | Generic | (a, b) |
| Y | 15 | (0xFB, 0xEF) | — | 22b−1.73 | 2(a−2)b+1 | All | 14 | (0xFB, 0xDB), (0x6F, 0xEF) | 1 | 23b−1.63 | 2ab/2 | (8, ∗) | 10 | (0xB1, 0x81), (0x06, 0xC6) | 3 | 24b−1.15 | 23ab/2 | All |
| N | 15 | (0xFB, 0xB) | 1 | 23b−1.73 | 2ab/2 | (8, ∗) | 11 | (0xB1, 0x81) | 3 | 24b−1.29 | 23ab/2 | All |
|
|