Research Article

Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function

Table 5

Known-key distinguishing and -word partial-collision attacks on 6-branch GFN-2.

LRKKDComp.Generic(a, b)

Y19(0xFBF, 0xFFE)24b–4.832(a−2)b+1(8, ∗)
17(0x6FF, 0xBFD)24b–4.7622(a−1)b+1All
16(0x6FF, 0x6EC), (0xBF1, 0xBFD)226b–4.592ab(8, ∗)

N17(0x6FF, 0x6FF)226b–4.672ab(8, ∗)