Distinguishing attack on five-round Feistel networks
Lars Ramkilde Knudsen, Håvard Raddum · Electronics Letters · 2003
Recently it was shown (by J. Patarin) how to distinguish a general five-round Feistel network from a random permutation using (23n/2) chosen plaintexts or (27n/4) known plaintexts. The present authors report improvement of these results and a distinguisher is presented which uses roughly 2n chosen plaintexts or roughly 23n/2 known plaintexts.