Integral Distinguishers for Reduced-Round Stribog
In January 2013, the stribog hash function officially replaced GOST R 34.11-94 as the new Russian cryptographic hash standard GOST R 34.11-2012. Stribog is an AES-based primitive and is considered as an asymmetric reply to the new SHA-3 selected by NIST. In this paper the authors investigate the structural integral properties of reduced version of the stribog compression function and its internal permutation. Specifically, they present a forward and backward higher order integrals that can be used to distinguish 4 and 3.5 rounds, respectively.