FOX系列算法是一类基于Lai-Massey模型设计的分组密码算法。该文首先评估低轮FOX64算法抵抗零相关线性分析的能力，给出4轮FOX64算法的零相关线性区分器。然后，利用零相关线性区分器与积分区分器的关系，首次得到4轮FOX64算法的积分区分器。最后，利用积分区分器分析5, 6, 7, 8轮FOX64算法，攻击的时间复杂度分别约为252.7, 2116.7, 2180.7, 2244.7次加密，数据复杂度为250个选择明文。该文首次给出攻击8轮FOX64/256时间复杂度小于穷举攻击的有效攻击。
FOX family block ciphers are based on Lai-Massey scheme. Firstly, the evaluation is performed on the ability of the reduced round FOX64 to resist zero-correlation linear cryptanalysis, and some 4-round zero- correlation linear distinguishers are presented. Then, by using the relation between the integral distinguishers and zero-correlation distinguishers, the 4-round integral distinguishers of FOX64 are found. Finally, the 4-round integral distinguishers are used to attack 5, 6, 7 and 8 rounds FOX64 with the time complexity of 252.7, 2116.7, 2180.7 and 2244.7 encryptions respectively, and the data complexity is 250 chosen plaintexts. This is the first paper pointing out that 8-round FOX64/256 is vulnerable against the statistical attack.