World War I changed the economics of cryptography. Radio replaced the courier and the telegraph line, but every message sent by radio was also received by the enemy. Armies now sent thousands of messages a day, and each one had to be encrypted by a clerk with a pencil and a codebook. This had to be done efficiently. Hand ciphers that were strong enough to resist analysis, such as double transposition or ADFGVX, were slow and error-prone under those conditions, while those fast enough to keep up were weak.
The solution was to build machines. A machine would be able to apply a transformation that was far too complicated to carry out by hand, change the substitution with every letter, and do it at typing speed. Between 1917 and 1919, inventors in the United States, Germany, the Netherlands, and Sweden independently arrived at the same design. Rotor machines dominated military cryptography until electronic ciphers replaced them in the 1960s, and some remained in service into the 1980s.
Rotor Machines
A rotor is a disk with one electrical contact on each face for every letter of the alphabet, 26 for the ISO basic Latin alphabet (English, French, and German). Each contact on the front is wired to a contact on the back in a scrambled order, so an electrical signal entering at position A might emerge at position Q. A single rotor is a monoalphabetic substitution cipher implemented with wires. Stacked in a row, several rotors apply several substitutions in series, and the composite mapping is still a monoalphabetic substitution, no stronger than a single rotor.
The difference is that rotors turn. After each letter is typed, the first rotor advances one position, so its wiring shifts by one contact relative to its neighbors, and the overall substitution changes.
When the first rotor completes a full turn, it advances the second rotor by one step, like the wheels of a mechanical odometer (here’s a video in case you’ve never seen one on a car built before the 1990s), and when the second completes a turn, it advances the third by one step.
Three rotors produce \(26^3 = 17{,}576\) distinct substitution alphabets before the sequence repeats. The machine implements a polyalphabetic cipher whose keystream is the sequence of rotor positions, and its period is 17,576, which is longer than any message. The operator typed the plaintext on a keyboard and read the ciphertext off a lamp board, one letter at a time, with no need for tables or arithmetic.
This solved the problem that broke the Vigenère cipher. Kasiski’s attack depended on a keystream with a period of a few letters. A rotor machine’s keystream had a period longer than the message, so the repetitions that Kasiski counted never appeared. The keystream was fully determined by the wiring of each rotor and the stepping sequence, so it was not random.
Enigma
_-_Museo_scienza_e_tecnologia_Milano.jpg/500px-Enigma_(crittografia)_-_Museo_scienza_e_tecnologia_Milano.jpg)
The most famous rotor machine is Enigma. Arthur Scherbius, a German electrical engineer, patented his design in 1918 and began selling it commercially in 1923, targeting banks and businesses. Commercial sales were poor. The German navy adopted a modified version in 1926, the army followed in 1928, and by World War II the German armed forces had tens of thousands of them. I assume most have been destroyed. Used ones sell for over $100,000 today. The machine was about the size of a typewriter and ran on a battery, so it could be used in a tent or a submarine (the 2000 film U-571 is a highly fictional story about an American submarine crew that boards a disabled German U-boat to capture an Enigma cipher machine).
How Enigma Worked
A signal from the keyboard passed through several components:
-
The plugboard. The operator connected pairs of letters with short cables, so that each cable swapped two letters. This swap was applied before the signal entered the rotors and again after it left.
-
Three rotors. The operator chose three rotors from a set of five and placed them in the machine in a chosen order, each turned to a chosen starting position.
-
The reflector. A fixed disk at the end of the rotor stack sent the signal back through the three rotors along a different path. The reflector made encryption and decryption the same operation: if A encrypted to R at some setting, R encrypted to A at the same setting.
The signal then passed back through the rotors and the plugboard and lit one of 26 lamps. The operator wrote down the lit letter and pressed the next key, which stepped the rotors before encrypting.
Every day, operators set up the machine with a daily base setting from a printed codebook that specified the rotor selection, rotor order, and plugboard connections for that day. The starting positions of the rotors, called the message key, were chosen by the operator for each message and sent, encrypted with the base setting, at the start of the message.
The Size of the Keyspace
The number of ways to set up the machine convinced the Germans that it was unbreakable. The choice and order of the rotors, their adjustable ring settings, their starting positions, and the plugboard connections together gave roughly \(10^{23}\) settings, about \(2^{76}\). At a billion settings per second, a search would take about three million years. (The arithmetic is in the appendix.) German cryptographers reviewed the machine repeatedly and concluded each time that it was secure.
Almost all of that number comes from the plugboard. The rotor order and starting positions together contribute only about a million settings, and that smaller number is the one the attacks had to search.
Enigma’s Weaknesses
Enigma’s weaknesses were in its structure and its operating procedures, and none of them were visible from the size of the keyspace:
-
No letter ever encrypted to itself. The reflector sent every signal back along a different path, so an A could become any letter except A. It was a side effect of the reflector, which made encryption and decryption the same operation. For a cryptanalyst, it was a filter. A guessed fragment of plaintext could be compared to the ciphertext, and any position where a letter matched itself was ruled out immediately.
-
The plugboard was a fixed substitution. However many cables were connected, the plugboard applied the same swap to every letter of the message. A monoalphabetic layer on either side of the rotors could be separated from the rotors and attacked on its own.
-
The rotors stepped predictably. The first rotor stepped every letter and the second rotor stepped about once per 26 letters. For most of a message, only one rotor moved, and the analysts could treat the other two as fixed.
-
Messages were predictable. Weather reports went out at the same time every morning and began with WETTER. Units with nothing to report sent KEINE BESONDEREN EREIGNISSE (“nothing special to report”). A sequence of plaintext that the analyst can guess is called a crib, and Enigma traffic was full of them.
-
The message key was sent twice. Until May 1940, operators encrypted the three-letter message key twice in a row at the start of every message, in case of typos or transmission errors. An analyst therefore knew that the first and fourth ciphertext letters came from the same plaintext letter, as did the second and fifth, and the third and sixth. Across hundreds of messages sent under the same daily settings, that pattern helped reveal the settings.
Breaking Enigma
In late 1932, before the Nazis came to power, mathematician Marian Rejewski of the Polish Cipher Bureau made his breakthrough against Enigma by exploiting operators’ practice of encrypting each message’s starting setting twice. Using permutation mathematics and documents obtained by French intelligence, he reconstructed its internal wiring without examining a military machine, pioneering the use of higher algebra in cryptanalysis.
By 1938, the Poles had built the bomba, an electromechanical device that automatically tested rotor settings. Germany then expanded the available rotors from three to five, with three still used at a time. This increased the possible rotor arrangements tenfold, making the required search too costly for Poland. In July 1939, weeks before Germany invaded Poland, the Polish Cipher Bureau shared its methods and wiring diagrams with British and French intelligence and arranged to supply replica Enigma machines.
British codebreakers at Bletchley Park developed an attack based on cribs. Designed by Alan Turing, with an improvement by Gordon Welchman, their bombe did not depend on double message keys, which the German army and air force abandoned in May 1940. It used interconnected electrical models of Enigma’s rotors to reject positions that would require contradictory plugboard connections, avoiding a search through every complete key. It tested all 17,576 positions for one rotor order in about twenty minutes, stopping at various candidates for further checking. (The contradictions are explained in the appendix.) More than 200 British bombes were built during the war.
Finding cribs required intelligence work: analysts studied operators’ habits, predictable messages, and captured documents. The Royal Air Force sometimes laid mines in selected areas to get the Germans to create reports containing names of those locations.
Germany’s introduction of a four-rotor Enigma on its main Atlantic U-boat network in February 1942 blocked decryption for about ten months. Codebooks captured from U-559 helped restore access by supplying cribs for weather reports sent in a three-rotor-compatible mode. Intelligence from Enigma and other high-level enemy ciphers became known as Ultra.
Even messages that could not be read provided information. Traffic analysis is the study of who is transmitting, to whom, when, how often, and at what volume, without reading the contents. Call signs identified units; a burst of messages from headquarters preceded an operation; and a submarine that transmitted at all revealed its position to direction-finding stations. Encryption hides the contents of a message but not the fact that it was sent. The same applies to encrypted Internet traffic today.
Lessons from Enigma
Enigma was never broken by brute force, and the size of its keyspace was irrelevant. It was broken because of three things:
-
Structural flaws. The reflector’s guarantee that no letter encrypts to itself, and the plugboard’s fixed substitution, removed most of the effective keyspace before any search began.
-
Predictable plaintext. The cribs came from the way the German military wrote messages, and the bombe would have been useless without them.
-
Operator behavior. Doubled message keys, reused settings, and operators who chose starting positions such as QWE from the keyboard row or the initials of their girlfriends handed the analysts shortcuts that the machine itself did not offer.
The Germans knew the machine’s design was in enemy hands, since commercial Enigmas had been sold openly for years, and they trusted it anyway because of the number of settings. Kerckhoffs’s principle was satisfied, but the machine had weaknesses that the number of settings did not reveal. Wartime German investigations never concluded that Enigma itself had been broken, and the break was made public only in 1974.
Other Machines
Enigma was one of many rotor machine designs, and later machines corrected its specific weaknesses. The American SIGABA of the late 1930s stepped its 15 rotors in an irregular, unpredictable pattern, so analysts could no longer treat most of the rotors as fixed, and no break of it has ever been published. The Soviet Fialka of 1956 used 10 rotors and a reflector that allowed a letter to encrypt to itself, which removed the filter the bombe had relied on.
The German high command did not use Enigma for its most important traffic. Messages between Berlin and the field marshals went by teleprinter, encrypted with the Lorenz machine, which generated a long stream of key bits and combined it with the message bit by bit. British analysts reconstructed the machine’s design from ciphertext alone, after an operator sent nearly the same long message twice with the same key settings. To break its traffic at a useful speed, they built Colossus, which worked by early 1944 and was the first programmable electronic digital computer. Its existence was kept secret until the mid-1970s, and the documents describing it were declassified in 2000.
Crypto AG, a Swiss company founded by the cipher-machine designer Boris Hagelin, sold encryption equipment to more than 120 governments after the war. In 1970, the American Central Intelligence Agency and the West German intelligence service secretly bought the company. For the next several decades, the machines sold to most of Crypto AG’s customers were designed so that their traffic could be read by the two agencies. The arrangement was reported by the Washington Post and the German broadcaster ZDF in February 2020. The customers trusted a design they could not examine, and the vendor was working for the adversary.
The Limits of Rotor Machines
Rotor machines made polyalphabetic substitution with a period of thousands of letters practical for a clerk in the field, eliminating the repetition that broke the Vigenère cipher. They produced keyspaces that put brute-force attacks permanently out of reach. Every cipher since has assumed that the adversary has a machine.
Enigma’s defeat also confirmed a lesson from the classical ciphers. The machine was one part of a system that included message formats, key sheets, operating procedures, and many operators, and the system was attacked wherever it was weakest. Automation helped both sides. It let a clerk apply an encryption that no hand cipher could match, and it let the attacker test settings at a rate no analyst could match. Traffic that could not be read still revealed who was communicating with whom.
Rotor machines also showed the limits of engineering without theory. Enigma’s designers reasoned about the number of settings because that was the number they could compute. They had no way to measure what a reflector or a fixed plugboard cost them, and no framework in which the question could be asked. Security still meant only that nobody had broken the cipher yet. What was missing was a theory that could say what a cipher had to do and whether a given design did it. Shannon’s theory of secrecy systems, written at Bell Labs during the war and published in 1949, supplied that framework.