Research Article
Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function
Table 6
Known-key distinguishing and
-word partial-collision attacks on 8-branch GFN-2.
| L | R | KKD | | Comp. | Generic | (a, b) |
| Y | 29 | (0xFBFF, 0xEFFF) | — | 25b−5.86 | 2(a−2)b+1 | (8, ∗) | 21 | (0x6FFF, 0xDBFF) | — | 25b−5.76 | 22(a−1)b+1 | All | 27 | (0xF01B, 0xC06F), (0x006F, 0xC1BF) | 2 | 25b−5.39 | 2ab | ¬(4, 8) | 20 | (0xF01B, 0xC01B), (0x006F, 0xC06F) | 5 | 27b−5.32 | 25ab/2 | All |
| N | 21 | (0xF01B, 0xF01B) | 5 | 27b−5.39 | 25ab/2 | All |
|
|