Research Article
Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function
Table 5
Known-key distinguishing and
-word partial-collision attacks on 6-branch GFN-2.
| L | R | KKD | | Comp. | Generic | (a, b) |
| Y | 19 | (0xFBF, 0xFFE) | — | 24b–4.83 | 2(a−2)b+1 | (8, ∗) | 17 | (0x6FF, 0xBFD) | — | 24b–4.76 | 22(a−1)b+1 | All | 16 | (0x6FF, 0x6EC), (0xBF1, 0xBFD) | 2 | 26b–4.59 | 2ab | (8, ∗) |
| N | 17 | (0x6FF, 0x6FF) | 2 | 26b–4.67 | 2ab | (8, ∗) |
|
|