- Integral cryptanalysis
cryptography ,**integral cryptanalysis**is a cryptanalytic attack that is particularly applicable toblock cipher s based onsubstitution-permutation network s. It was originally designed byLars Knudsen as a dedicated attack against Square, so is commonly known as the**Square attack**. It was also extended to a few other ciphers related to Square:CRYPTON ,Rijndael , andSHARK .Stefan Lucks generalized the attack to what he called a "saturation attack" and used it to attackTwofish , which is not at all similar to Square, having a radically differentFeistel network structure. Forms of integral cryptanalysis have since been applied to a variety of ciphers, includingHierocrypt , IDEA, Camellia, Skipjack,MISTY1 ,MISTY2 ,SAFER++ ,KHAZAD , and "FOX" (now calledIDEA NXT ).Unlike

differential cryptanalysis , which uses pairs of chosen plaintexts with a fixedXOR difference, integral cryptanalysis usesset s or evenmultiset s of chosen plaintexts of which part is held constant and another part varies through all possibilities. For example, an attack might use 256 chosen plaintexts that have all but 8 of their bits the same, but all differ in those 8 bits. Such a set necessarily has an XOR sum of 0, and the XOR sums of the corresponding sets of ciphertexts provide information about the cipher's operation. This contrast between the differences of pairs of texts and the sums of larger sets of texts inspired the name "integral cryptanalysis", borrowing the terminology ofcalculus .**References*** cite conference

