The authors present a new divide and conquer key recovery attack on th
e retail MAC based on DES, which is a widely used algorithm to compute
a message authentication code (MAC). The attack requires 2(32.5) know
n text-MAC pairs and 3.2(56) off-line computations to find the 112 bit
key.