In this paper the newly proposed RMAC system is analysed and a generic attack is presented. The attack can be used to find one of the two keys in the system faster than by an exhaustive search. Also, a serious attack on RMAC used with triple-DES is presented.
Lars R. Knudsen, Tadayoshi Kohno