A new attack on block ciphers is introduced, which is termed integral crypt
analysis. It relies on similar principles to differential cryptanalysis, bu
t is based on different statistics. It is shown that this method is more ef
fective than differential cryptanalysis in attacking SAFER+.