How easy is collision search? Application to DES

Abstract

Given a cryptographic algorithm f (depending upon a fixed message m and a key k), a pair of keys with collision k 1 and k 2 (in short, a collision) are keys such that f(m, k 1) = f(m, k 2).