A new message authentication code (MAC) algorithm is proposed, which i
mproves the popular retail MAC based on the data encryption standard;
it has the same complexity, but provides better resistance against key
recovery attacks. Ln addition, a new key recovery attack on the retai
l MAC is presented, requiring a single known text-MAC pair and 2(56) o
nline MAC verifications.