Strength of SAFER+ against Differential Cryptanalysis
An exhaustive study of SAFER+ has shown that all 5-round characteristics have probalility significantly smaller than
SAFER+ with six or more rounds (but not fewer) is secure against differential cryptanalysis
For a desirabel margin of safey, we have chosen 8 rounds for SAFER+ with the 128-bit key schedule. This also has the effect that each byte of the user-selected key affects every byte position within the round keys exactly once. (This is also true for the 192-bit and 256-bit key schedule.)