Tongxin xuebao (Jul 2012)
Improved integral distinguisher of Grøstl-512
Abstract
Firstly,the distinguisher of Grøstl-512 proposed by Minier in CANS 2010 was corrected.Then,the integral distinguisher of Grøstl-512 compression function was improved.By using the saturation technique new 11-round integral distinguishers of P function and Q function were proposed.Whereas the SHA-3 competition focuses the attacks of hash functions,the proposed analysis on integral distinguish reflect the randomness of the compression function,which is of great significance to design new hash function.