n 2 = s ( p 0 ⊕ k 0 ) ⊕ s ( p 5 ⊕ k 5 ) ⊕ 2 ⋅ s ( p 10 ⊕ k 10 ) ⊕ 3 ⋅ s ( p 15 ⊕ k 15 ) ⊕ s ( k 15 ) ⊕ k 2
n 5 = s ( p 4 ⊕ k 4 ) ⊕ 2 ⋅ s ( p 9 ⊕ k 9 ) ⊕ 3 ⋅ s ( p 14 ⊕ k 14 ) ⊕ s ( p 3 ⊕ k 3 ) ⊕ s ( k 14 ) ⊕ k 1 ⊕ k 15
n 8 = 2 ⋅ s ( p 8 ⊕ k 8 ) ⊕ 3 ⋅ s ( p 13 ⊕ k 13 ) ⊕ s ( p 2 ⊕ k 2 ) ⊕ s ( p 7 ⊕ k 7 ) ⊕ s ( k 13 ) ⊕ k 0 ⊕ k 4 ⊕ k 8 ⊕ 1
n 15 = 3 ⋅ s ( p 12 ⊕ k 12 ) ⊕ s ( p 1 ⊕ k 1 ) ⊕ s ( p 6 ⊕ k 6 ) ⊕ 2 ⋅ s ( p 11 ⊕ k 11 ) ⊕ s ( k 12 ) ⊕ k 15 ⊕ k 3 ⊕ k 7 ⊕ k 11