Research Article

Known-Key Distinguishing and Partial-Collision Attacks on GFN-2 with SP F-Function

Table 6

Known-key distinguishing and -word partial-collision attacks on 8-branch GFN-2.

LRKKDComp.Generic(a, b)

Y29(0xFBFF, 0xEFFF)25b−5.862(a−2)b+1(8, ∗)
21(0x6FFF, 0xDBFF)25b−5.7622(a−1)b+1All
27(0xF01B, 0xC06F), (0x006F, 0xC1BF)225b−5.392ab¬(4, 8)
20(0xF01B, 0xC01B), (0x006F, 0xC06F)527b−5.3225ab/2All

N21(0xF01B, 0xF01B)527b−5.3925ab/2All