The author presents a new chosen-text attack on the CBC-MAC, which bas
ed on DES, is a widely used algorithm to compute a message authenticat
ion code (MAC), Using DES with a MAC of size 35 bits, the attack requi
res similar to 2(17) chosen texts and two known texts.