Enigma: the machine that gave itself away

Three toothed wheels ringed with notch marks on one axle above a keyboard, and at the back a block where the wiring loops back on itself.

Caesar's cipher from the previous chapter has one big leak: what is common stays common. In English the E is the most used letter, so the letter that turns up most often in the ciphertext is the E. Count and done. But what if the lock is reset after every single letter? Germany built a machine for that in the 1930s, and that machine is called Enigma. This site is named after it.

Words you might need

Rotor
A wheel with 26 contacts on each side and 26 criss-crossed wires soldered inside. A letter goes in, a different one comes out. There are three of them side by side, and after every keypress the right-hand one turns a step.
Reflector
A block at the back that sends the current back. So the letter first runs through the three rotors, bounces back, and runs through them again in reverse order. That one part makes the machine what it is, including its flaw.
Setting
The three letters you see through the little windows before you start. That is the key for the message. You and the receiver have to set exactly the same three.
Notch
A cut in the rim of a rotor. When it comes past, the wheel takes its neighbour along by one step, like the odometer of a car.
Guess
A piece of text you suspect is in the message. The English word for it is a crib. Down below it becomes the tool you start breaking with.

A Caesar that jumps after every letter

With Caesar you shift every letter by the same amount. With Enigma the letter runs through three wheels that each have their own criss-cross wiring, bounces back at the end, and comes through again. That on its own is still one fixed substitution. The difference is in the last line of the explanation above: after every keypress a wheel turns. The substitution you use for the second letter is no longer the one you used for the first.

The right-hand rotor turns on every keypress. Once it has gone round fully, its notch pushes the middle one a step on, and that one in turn pushes the left-hand one. Like the wheels of an odometer, except that each wheel has a cipher inside it. Only after 26 × 26 × 26 = 17,576 keypresses does the machine stand exactly as it started.

Type on the machine

Everything happens in your browser. Nothing is sent to the server.

  1. Click Turn the handle. Your message comes out as ciphertext, and you see where the wheels stopped.
  2. Put the setting back to QFR, paste the ciphertext into the top box and click again. Your message comes back. The same operation, both ways.
  3. Click The same key ten times. Ten A's in, and look at what comes out.
  4. Click Does a letter ever become itself? and read the answer carefully. The next part of this chapter is about that.

Why nobody broke it by counting

Count how many ways there are to set up such a machine. You pick three rotors out of a box of five, and the order matters: that is 60 possibilities. You put them in one of 17,576 settings. And at the front there is a plugboard that swaps ten pairs of letters, good for 150,738,274,937,250 possibilities.

60 × 17,576 × 150,738,274,937,250 ≈ 1.6 × 1020

A hundred and sixty quintillion settings. For comparison: about 4 × 1017 seconds have passed since the Big Bang, so this is more than three hundred times that. Trying them all was not an option, not in 1940 and not by hand now either. And the letter counting that breaks a Caesar in ten minutes does nothing at all here, because the E has become something else at every keypress.

This is the chapter where you would expect the story to stop. It does not stop.

The one wire that gave it away

Look at the reflector again. The current goes there and comes back along a different wire. Now the question: what if you press an A and the machine also made an A of it? Then on the way back the current would have to take exactly the same path as on the way there. Through the same wire, both ways at once. That cannot happen.

So: no letter ever becomes itself. That is not a coincidence and not sloppiness, it follows inevitably from that one block at the back. And it is exactly what made the machine convenient: because the way there and back are the same, you never had to choose between encrypting and decrypting. One setting, one operation.

A property like that is never free. What made it easy to operate handed the attacker a rule that is always true. And a rule that is always true is a sieve.

The sieve

German messages often started the same way. A weather report at six in the morning, every day, with the word Wetterbericht in it. If you know that word is in there but not where, you can lay it under the ciphertext and slide it along, position by position. Anywhere the word meets the same letter as the ciphertext beneath it, you know for certain: it is not here. Because a letter never becomes itself.

You still do not know which setting it was. But you have cut the number of places you have to search right down, without trying a single setting.

Slide the guess along the message

Everything happens in your browser. Nothing is sent to the server.

  1. Click Slide it. Under the ciphertext a bar appears with a dot at every place the guess can sit, and an X where it clashes.
  2. Count the dots. That is how many places are left out of the whole message.
  3. Change the guess to NOTHINGSPECIAL and slide again. Different guess, different bar.
  4. Type a guess that is certainly not in there and see what happens.

In chapter 9.5 you take the last step: there you get exactly this message, and you look for the setting that makes it readable. All 17,576 of them, because that is what is left once you leave the plugboard out. Your browser will not take a second over it.

Who did it

Not the British first. In 1932 the Polish mathematician Marian Rejewski reconstructed the wiring of the rotors without ever having seen one, purely by thinking about what happens when you put substitutions one after another. Together with Jerzy Różycki and Henryk Zygalski, Poland was reading along years before the war. Just before the invasion they handed everything to the British and the French.

At Bletchley Park, Alan Turing and Gordon Welchman built on that: a machine, the Bombe, that took a guess as its starting point and ran through all the settings that did not immediately contradict themselves. That guess is exactly what you slid along above.

What you take from this: the mathematics of Enigma was excellent for its time. What broke it was a property that made it comfortable to operate, plus people who typed the same word in every morning. That is the same lesson as in chapter 9.5, only eighty years earlier.

This is math: permutations

One setting of an Enigma is a permutation of 26 letters: a way of shuffling the alphabet in which every letter gets exactly one place. Because of the reflector that permutation is of a very particular kind. It is its own inverse — apply it twice and you are back where you started, which is exactly why encrypting and decrypting are the same thing here. And it has no fixed points at all: no letter stays where it was. Permutations like that only exist if you can split the alphabet neatly into thirteen pairs, and on 26 letters there are 7,905,853,580,625 of them. Rejewski broke the machine by looking at what happens when you put such permutations one after another: the little cycles that then appear always come in pairs of equal length. That is a theorem from group theory, the same subject you meet in chapter 7.2 when you add points. The same mathematics, thirty years earlier, and back then it won a war.