Research Article

Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function

Table 4

Known-key distinguishing and -word partial-collision attacks on 4-branch GFN-2.

LRKKDComp.Generic(a, b)

Y15(0xFB, 0xEF)22b−1.732(a−2)b+1All
14(0xFB, 0xDB), (0x6F, 0xEF)123b−1.632ab/2(8, ∗)
10(0xB1, 0x81), (0x06, 0xC6)324b−1.1523ab/2All

N15(0xFB, 0xB)123b−1.732ab/2(8, ∗)
11(0xB1, 0x81)324b−1.2923ab/2All