How did Enigma work, and how was it cracked?

How did Enigma work, and how was it cracked?

A wooden box of wires kept German radio messages secret for a whole war. Here's how it scrambled them, and how a handful of mathematicians unscrambled them.

FIG_1 [ AN ENIGMA I ]
Fig. 1An Enigma I with its lid open, typing HELLO twice. Watch the lamps: the second HELLO comes out completely different from the first, because the right-hand wheel turns one step every time a key goes down. Tap to start again.

The first real Enigma I saw was sitting in a glass case, and honestly, it was a bit of a let-down. I'd expected something sinister. What I got was a scuffed wooden box, a bit bigger than a shoebox. It had a typewriter keyboard, a grid of little round windows and three metal wheels poking up through the top. It looked like something you'd find in your grandad's shed.

That box carried the secrets of a whole army, navy and air force. German officers typed their orders into it. Out came gibberish that could be sent safely by radio. Anyone could listen in. Without the right settings, though, nobody could read it, and the Germans were sure that nobody ever would.

They were wrong. Mathematicians in Poland broke it before the war even started. Then, at a country house north of London called Bletchley Park, thousands of people kept breaking it, day after day, until 1945.

So this chapter has two halves. The first half takes the machine apart and shows how one key press turns into a different letter. The second half is the story of how people beat it. The good news is that the two halves share one simple idea, and by the end you'll be able to spot it.

  1. Radio messages can be heard by anyone.Codes
  2. Simple codes leak their secret through letter counts.Wiring
  3. The machine is huge, but its users had habits.Patterns
  4. There are too many settings to try by hand.Machines
Part A · 1

Secrets over the radio

Radio changed war. A general could talk to a tank, a ship or a plane hundreds of kilometres away, in seconds. The catch is that radio goes everywhere. If your own side can hear you, so can the other side. So every message had to be scrambled before it was sent and unscrambled when it arrived.

The normal message is called the plaintext. The scrambled version is the ciphertext. The method for turning one into the other is a cipher, and the small secret that makes it work on a given day is the key.

The oldest trick is to swap every letter for another one. A becomes Q, B becomes D, and so on, the same way every time. That's a substitution cipher. Julius Caesar used a simple version, sliding the whole alphabet along by three letters. You might have made one at school with a paper wheel.

The trouble is that a substitution cipher hides the letters but not the pattern. In English, E turns up far more than any other letter, followed by T, A and O. Swap E for X and you still have a ciphertext full of X's. Count the letters, match the most common ones to E, T and A, and the words start to fall out. This is called frequency analysis. Arab scholars wrote about it more than a thousand years ago. Have a go.

FIG_2 [ COUNTING LETTERS ]
Tap a bar, then type the letter you think it stands for.
Fig. 2A message scrambled with a simple swap. The dark bars count each scrambled letter. The pale ones show how often each letter turns up in ordinary English. Tap a bar and type a letter to make a guess, or try Match by count to pair them up by height and then fix the mistakes.

Matching by count gets you most of the way, but not all of it. Short messages don't follow the averages exactly, so a few letters come out wrong. Then you fix them by eye: "THE" is easy to spot, and once you have it, the rest falls into place.

So if you want a cipher that survives this, you can't let any letter always turn into the same thing. In 1918 a German engineer called Arthur Scherbius filed a patent for a machine that did exactly that. It used wired wheels that turn as you type, so the swap changes with every single letter. He called it Enigma. A version of it, the Enigma I, became the standard machine of the German army and air force in the 1930s.

Part A · 2

A box of wires

The Enigma I is about 34 cm wide, 28 cm deep and 15 cm tall with its lid shut, and it weighs about 12 kg. It's not a computer. There are no chips and no valves, just a battery, some wires, a few springs and 26 little light bulbs.

At the front is a keyboard with 26 keys. The letters aren't in the order you're used to. German typewriters use a layout called QWERTZ, with the Z where an English keyboard has its Y. Enigma's keys follow it closely: QWERTZUIO on the top row, ASDFGHJK in the middle and PYXCVBNML along the bottom. Behind the keys is the lampboard, 26 bulbs under round glass windows in the same three rows. Press a key and one lamp lights up. That lamp is the scrambled letter.

FIG_3 [ INSIDE THE BOX ]
Fig. 3The Enigma I pulled apart. The cover over the wheels lifts off, the reflector, three rotors and entry wheel come out as a set, and the battery lifts out of its box. Everything else stays fixed in the case. Positions inside are taken from photos, so they're close but not exact. Tap to put it back together.

A flat 4.5-volt battery, like the ones in old torches, powers the whole thing. The interesting part is what the current flows through on its way from the key to the lamp. Under the cover at the back sit three wheels called rotors. Each one is a thick disc. It has 26 metal contacts on one face and 26 on the other, and inside, 26 wires join them up in a jumbled order. So a rotor is a substitution cipher you can hold in your hand.

The army had five different rotors, numbered I to V, each wired differently. Each day the operator picked three of them and put them in a set order. On the right of the rotors is a fixed entry wheel, where the current goes in. On the left is a fixed wheel called the reflector, which sends the current back the way it came. At the front, behind a wooden flap, there's a panel of sockets called the plugboard. It swaps pairs of letters on the way in and again on the way out.

That's the whole machine. Let's follow one key press through it.

Part A · 3

One key press, start to finish

Press a key and two things happen, in this order. First, the key pushes a lever that turns the right-hand rotor one step. Only then does the key close a switch and let the current flow. That order matters, and we'll come back to it.

Then the current goes on a little trip. From the key it goes to the plugboard, which might swap it for another letter. Then it enters the entry wheel, passes through the right, middle and left rotors, and hits the reflector. The reflector is wired in pairs, so it turns the current round and sends it back through the left, middle and right rotors on a different path. Out it comes, through the plugboard again, and into a lamp. That's nine swaps for one letter, if you count the reflector.

FIG_4 [ ONE KEY PRESS ]
Press
Fig. 4The real wiring of rotors I, II and III and reflector B, with one plug swapping A and E. Orange is the trip in, blue is the trip back. Every press turns the right-hand rotor first, so pressing the same key again gives a new path. Tap the picture or pick a letter.

Each rotor is wired so that a letter coming in on the right leaves on the left as a different letter. Rotor I, for example, sends A to E and B to K. But a rotor can turn. Turn it one step and every contact moves along by one, so the same wire now joins up different letters. That's the whole point of it.

You can make a tiny one with paper. Write A to Z down two strips and lay them side by side, a hand's width apart. On a third piece of paper between them, draw lines joining the letters in any jumbled order. Now slide that middle piece down by one letter. Every line now joins a different pair. That middle piece is a rotor.

Each rotor also has an alphabet ring around its edge. The letters on it show through a little window in the cover, so the operator can see how each rotor is set. The ring can slip round the rotor and be clipped in any of 26 positions. That position is the ring setting, and it changes which letter shows in the window for a given position of the wires.

FIG_5 [ INSIDE A ROTOR ]
A (01)
Fig. 5The real wiring of rotor I. Each grey line is one wire inside the rotor. Slide the ring setting and the ring turns round the wires. The notch goes with it, because it's cut into the ring. The wiring doesn't change at all.

Look closely at the ring and you'll see a small cut in its edge called the notch. On rotor I it sits by the letter Q. The notch is what makes the next rotor move, and it's the key to how the whole machine counts.

Part A · 4

Wheels that count

The rotors move a bit like the numbers on an old car's mileage counter. The right-hand rotor steps once for every key you press. Once per trip round, when its notch comes round, it pushes the middle rotor on by one. And once per trip round of the middle rotor, the middle one pushes the left one.

Each rotor's notch sits in a different place. Rotor I pushes its neighbour as it moves from Q to R. Rotor II does it from E to F, and rotor III from V to W. Rotor IV goes at J to K, and rotor V at Z to A. Code breakers loved this, because spotting where the middle rotor jumped told them which rotor was on the right.

There's a quirk, though, and it's a good one. The pushing is done by three small levers called pawls, one behind each rotor. Each pawl rests on the edge of the ring of the rotor to its right. When the notch comes under it, the pawl drops in and pushes. The middle pawl pushes the middle rotor's ratchet, but the left pawl pushes against two things at once: the left rotor's ratchet and the middle rotor's own notch. So when the middle rotor reaches its notch, it gets pushed again on the very next key press, along with the left rotor. The middle rotor steps twice in a row. This is called the double step.

FIG_6 [ THE DOUBLE STEP ]
Fig. 6Rotors I, II and III, starting at A D U. Press a key a few times. The right-hand rotor steps every time. Going from V to W, it pushes the middle rotor to E. E is the middle rotor's own notch, so on the next press the middle rotor steps again, to F, and takes the left rotor with it. A drawing of the mechanism, not to scale.

Without the double step, the three rotors would behave like a perfect counter and repeat after 26 × 26 × 26 = 17,576 key presses. The double step skips one middle position each time the left rotor moves. So the machine actually repeats after 26 × 25 × 26 = 16,900 presses. That's still far longer than any message, which were usually kept to a few hundred letters.

Part A · 5

Swapping pairs at the front

The rotors alone were not enough for the army. So from 1930 the military machines got an extra layer: the plugboard. In German it's the Steckerbrett, and the code breakers ended up calling a plugged pair a stecker.

Under each letter on the plugboard there's a pair of sockets. A cable with two plugs joins two letters together and swaps them, both ways. Plug A to E and pressing A sends current in at E, and anything leaving at E lights lamp A. Letters without a cable go straight through.

FIG_7 [ THE PLUGBOARD ]
Fig. 7The plugboard, close up, with the ten cables from one day's key. Each cable swaps its two letters both ways. Six letters have no cable and pass straight through. Tap a letter to see what it turns into. Many army machines marked the sockets with numbers 01 to 26 instead of letters.

At first the operators used six cables. By the start of the war it was ten, which became the normal number for the rest of it. Ten is a clever choice. It turns out to give nearly the most possible ways of plugging the board: 150,738,274,937,250 of them. Eleven cables would have given a bit more, but ten was treated as the practical limit, and the machine came with twelve so there were two spares.

The plugboard doesn't change as you type, which turned out to be a weakness. But it multiplied the number of possible settings by an enormous amount, and that was the bit the Germans trusted.

Part A · 6

The mirror at the end

Now for the cleverest part of the design, and also its biggest mistake. The reflector has 13 wires, each joining two letters. Reflector B, the one used for most of the war, joins A with Y, B with R, C with U, and so on. Because the current goes through every other part twice, once in and once back, the whole machine at any one moment is just 13 swapped pairs.

That has a lovely result. If pressing A lights N, then at the same rotor position pressing N lights A. So the receiver doesn't need a separate decoding machine, or even a switch. They just set up the same settings, type in the ciphertext, and the plaintext lights up. Scrambling and unscrambling are the same job.

But there's a catch. Since the current always has to come back on a different wire, no letter can ever turn into itself. Press A and you'll get 25 possible lamps, never A. It sounds harmless. It isn't, and it's the hole the whole second half of this chapter climbs through.

FIG_8 [ 13 PAIRS ]
Fig. 8The whole machine at one moment, as 13 swapped pairs. Every line joins two different letters. When the rotor steps, the pairs change completely, but no line ever loops a letter back to itself. Tap to step the rotors.

That's all of it: keyboard, plugboard, entry wheel, three rotors that count with a hiccup, a reflector and 26 lamps. Here's a working one. It uses the real wiring of all five army rotors and reflector B, and the stepping, double step included, works just like the real machine.

FIG_9 [ A WORKING ENIGMA ]
In–
Out–
Fig. 9Type on your keyboard or tap the keys. The settings start on rotors I, II and III, rings and start at A, no plugs: type AAAAA and you should get BDZGO, the standard check for any Enigma simulator. Load a wartime example sets up a worked example from the German Wikipedia article on Enigma, built to the army's own rules. Type its ciphertext back in and the German plaintext reappears.

Try typing a long string of the same letter. You'll never see that letter on the lamps. And if you reset and type the output back in, you get your original message. Same machine, same settings, both ways.

Part A · 7

The daily key

Every unit had a printed sheet of settings for the month, one line per day, kept under lock and key. Each line said which three rotors to use and in what order, the three ring settings, and which ten pairs of letters to plug together. That's the daily key. Everyone on the same network used the same one, so they could all read each other's messages.

Setting up took a few minutes. The operator lifted out the rotors and clicked each one's ring round to the day's setting. Then the three rotors went back in, in the right order, and the inner cover came down. The cables went into the plugboard, and the wooden flap closed over them. Last of all, the operator turned the finger wheels until the right letters showed in the windows. Get any one of those wrong and the message came out as rubbish at the other end.

For each message, the operator also chose a fresh starting position for the rotors, three letters like RTZ. That's the message key. It had to reach the other end somehow, so it was sent at the start of the message, itself scrambled. How exactly that was done changed during the war, and those changes matter a lot in the second half.

So how many settings are there? Here's the sum, step by step:

FIG_10 [ HOW MANY KEYS? ]
Fig. 10Each bar is ten times longer for every extra digit, so the plugboard really is the giant here. The usual figure, 158,962,555,217,826,360,000, leaves out the ring settings. They multiply it by up to 676 more, but they mostly just change when the rotors turn over, so code breakers could often work them out last.

With five rotors, there are 5 × 4 × 3 = 60 ways to pick three and put them in order. Each rotor can start in 26 positions, so three of them give 26 × 26 × 26 = 17,576 starts. Then the plugboard adds its 150 million million or so. Multiply them and you get about 159 million million million. Try one setting a second and you'd need far longer than the universe has existed.

I've left the ring settings out of that big number, like most books do. The left ring changes nothing you couldn't get by turning the left rotor, so only the other two count. And they mostly decide when the rotors turn over. If you do count them, it's up to 676 times more, around 1023. The full working is in the maths box at the end.

No wonder the Germans felt safe. Even if the enemy captured a machine and knew every wire, they'd still have to find the day's key among all of those. And yet that's more or less what happened, starting in Warsaw in 1932.

Part B · 1

Three mathematicians in Poland

Poland had good reason to worry about German radio. In the late 1920s its Cipher Bureau started hearing army messages it couldn't read at all. The Bureau's old hands were language experts, and languages weren't going to crack a machine. So in 1929 it set up a secret code-breaking course for maths students at Poznań University, where many students spoke German.

In September 1932, three of the best joined the Bureau full time in Warsaw: Marian Rejewski, who was 27, Jerzy Różycki and Henryk Zygalski. Rejewski was given the Enigma.

He had a copy of a commercial Enigma, but not the army's wiring. He also had help from an unlikely place. A German called Hans-Thilo Schmidt, who worked in the army's own cipher office, had been selling secrets to French intelligence. The French officer in charge, Gustave Bertrand, passed some of them to Poland. In December 1932, Rejewski was handed copies of some German papers. Among them were the daily keys for September and October that year.

The keys alone didn't tell him how the rotors were wired. That came from the way messages began. In those years, everyone on a network set their rotors to the same start for the day. Then each operator typed their own three-letter message key twice, in case radio static garbled it. RTZ became RTZRTZ, which came out as six scrambled letters at the very start of the message.

That doubling was the gift. The first and fourth letters of every message stood for the same letter, scrambled at two rotor positions that were exactly three key presses apart. Same for the second and fifth, and the third and sixth.

Here's how that works with real letters. Say one message starts DMQ VBN. Whatever the key's first letter was, the machine turned it into D at the first press and into V at the fourth. So D and V are linked. Another message might start VON PUY, which links V to P. Keep going through a day's messages and the links join up into chains, until one comes back round to D. Nobody knows the key letters yet, but the chains are already there to be counted.

FIG_11 [ CHAINS OF LETTERS ]
Plugboard
Fig. 11A day's messages from a simulated day in 1932, each starting with its doubled message key. Join each message's 1st letter to its 4th and you get closed chains of letters, which mathematicians call cycles. Chains of the same length always come in pairs. Switch the plugboard off: the letters move around, but the lengths stay exactly the same.

Rejewski treated each rotor position as a permutation, which is just a maths word for a way of shuffling the 26 letters. Following first letters to fourth letters across a day's messages gave him a combined shuffle, and he could write it down as closed chains, or cycles. Then he spotted something that changed everything. The plugboard renames the letters in those chains, but it can't change how long they are.

That meant the lengths of the chains depended only on the rotors. With six possible rotor orders and 17,576 starting positions, there were only 105,456 rotor settings to worry about. That's a lot, but it's a number you can make a list of.

First, though, he needed the wiring. Using the stolen keys, he could peel the plugboard off his equations and solve for the right-hand rotor. The two months fell in different quarters of the year, when the rotor order changed, so they put different rotors on the right. That gave him two rotors, and from there he worked out the third and the reflector. Near the end of 1932, sitting at a desk with pencil and paper, he had rebuilt the army's Enigma without ever seeing one. The Poles had copies made, and from early 1933 they were reading German army messages.

To find each day's settings quickly, Rejewski built a device called the cyclometer: two sets of rotors wired together that showed the chain lengths for any setting. With it, the team made a card catalogue of the chain lengths for all 105,456 settings. It took more than a year. But once it was done, finding a day's rotor order and positions took about a quarter of an hour.

Różycki, meanwhile, found a way to work out which rotor was on the right, using the fact that each rotor turns its neighbour over at a different letter. It became known as the clock method. All three were now reading Enigma as a matter of routine. It wasn't going to last.

Part B · 2

Holes in paper

On 15 September 1938, the Germans changed the rules. Operators no longer used one shared starting position for the whole day. Each one now picked their own, sent it in plain view, and then scrambled their doubled message key from there. The catalogue depended on everyone starting from the same place, so overnight it stopped working.

The doubling was still there, though, and Zygalski found a new way to use it. Every so often, about one message in eight, the same letter appeared twice in the scrambled key: in the 1st and 4th places, say, as in SZVSIK. The Poles called these females. A female can only happen at some rotor positions, roughly two in every five, and the code breakers could work out which ones in advance.

Zygalski's idea, now known as Zygalski sheets, was to punch those positions into sheets of card. Each sheet stood for one position of the left rotor. Its grid covered all 676 positions of the other two, drawn twice each way so it could be slid around. A hole meant "a female could happen here". A full set was 26 sheets for each rotor order, each with about a thousand holes, all cut out by hand.

FIG_12 [ ZYGALSKI SHEETS ]
Fig. 12Sheets stacked on a light table, one for each message with a female, each slid along to match that message's starting position. The holes are worked out from the real rotor wiring. Light only gets through where every sheet has a hole, and after about ten sheets just one spot is left. The real team didn't know which sheets to use for the left rotor, so they tried all 26 options. This shows the right one. Tap to restack.

Stack enough sheets in the right place and only one hole lets the light through. Where it sits gives the rotor order and the ring settings, and from there the plugboard could be worked out by hand.

Rejewski came up with a machine for the same job, the bomba. Each one held six sets of Enigma rotors and ran through all 17,576 positions looking for females, ticking loudly as it went. The name means "bomb", and one of the technicians said it was because of the noise. Six were built by November 1938, one for each rotor order, and they could find a day's key in about two hours.

Then, on 15 December 1938, the Germans gave every operator two more rotors, IV and V, to pick from. Six rotor orders became sixty, and the work went up tenfold. On 1 January 1939 they started using up to ten plugboard cables too, which hurt the bomba badly, because it relied on letters that had no cable. The Poles worked out the new rotors' wiring, but they didn't have the money or the people to build fifty-four more machines and punch hundreds more sheets.

So with war clearly coming, they decided to share. On 25 and 26 July 1939, in a forest near the village of Pyry just south of Warsaw, the Poles met French and British code breakers: Bertrand and Henri Braquenié from France, and Alastair Denniston, Dilly Knox and Humphrey Sandwith from Britain. The guests were amazed. Knox had been stuck for months. He hadn't even guessed that the entry wheel was wired in plain alphabetical order. The Poles showed them everything, and promised each side a copy of their Enigma. Five weeks later, Germany invaded Poland.

The Cipher Bureau burned what it couldn't carry and fled. Rejewski, Różycki and Zygalski crossed into Romania on 17 September 1939. By 20 October they were at work again, at a French base near Paris called PC Bruno, in touch with Bletchley Park by teleprinter.

Part B · 3

Bletchley Park and the guessed words

Britain's code breakers had moved out of London to Bletchley Park in August 1939. On 4 September, the day after Britain declared war, two Cambridge mathematicians reported there: Alan Turing and Gordon Welchman. In January 1940, with sheets punched at Bletchley and carried to the Polish team, who were now working in France, the first wartime messages were read.

But everyone knew the doubled message key couldn't last, and on 1 May 1940 the Germans dropped it. The sheets were finished. Bletchley needed a way in that didn't depend on how messages began. The answer was the crib.

A crib is a guess at a word or phrase that's in the message. Army messages are dull and full of repeats. That's wonderful if you're the enemy. Weather stations sent WETTERVORHERSAGE, "weather forecast", at the same time every morning. Units reported KEINE BESONDEREN EREIGNISSE, "nothing special to report". Messages started with ANX, which meant "to", followed by a space marker.

Finding cribs was a job in itself. Bletchley had people who did nothing but study the traffic: which stations sent what, at what time of day, and how their messages usually began. A weather station that sent the same kind of report at the same time every morning was a gift.

You still need to know where the crib sits in the ciphertext, and this is where Enigma's flaw comes in. No letter ever turns into itself. So slide your crib along the ciphertext. Anywhere a crib letter sits on top of the same letter, that spot is ruled out. They called that a crash.

FIG_13 [ DRAG THE CRIB ]
Drag the crib or use the buttons. Red letters are crashes.
Fig. 13A real Enigma scrambled this message, which contains the word WETTERVORHERSAGE somewhere. Slide the crib along. A red letter means the crib letter and the ciphertext letter are the same, which Enigma can't do, so that position is ruled out. About half the positions survive, which is why a crib on its own isn't enough.

Once a crib is lined up, each pair of letters is a clue. Say crib letter E sits over ciphertext letter T at the 2nd position. That means: at the 2nd key press, with the plugboard in place, E and T were swapped. Draw every pair as a line between two letters, labelled with its position, and you get a little map of clues. Bletchley called it a menu.

The good bits of a menu are its loops, where you can follow the lines from a letter and come back to it. A loop is a chain of swaps that has to add up exactly, and that makes it a very strict test.

FIG_14 [ A MENU ]
Fig. 14The menu from the crib in Fig. 13, at the position that was really used. Each line says "these two letters were swapped at this key press". The orange lines make three closed loops: R and E are linked twice, at presses 5 and 11, and E, A and H form a triangle, as do O, W and G. The O, W, G loop is in a separate piece that doesn't reach the test letter, so a Bombe couldn't use it.
Part B · 4

A machine that looks for contradictions

Turing's big idea was to test a menu with a machine. He called it the Bombe, after the Polish bomba, but it worked in a completely different way. It was built by the British Tabulating Machine Company at Letchworth, with Harold "Doc" Keen as its engineer. The first one, called Victory, started work at Bletchley on 18 March 1940.

A Bombe is a big metal cabinet, about 2.1 metres wide, 2 metres tall and 60 centimetres deep, and it weighs about a ton. On the front are 108 drums in three banks. Each drum copies one Enigma rotor, and each vertical set of three copies a whole set of rotors, so one Bombe holds 36 Enigmas' worth of wheels. The drums are painted by which rotor they copy: red for I, maroon for II, green for III, yellow for IV and brown for V.

FIG_15 [ THE BOMBE ]
Fig. 15A British Bombe, drawn to the real cabinet size. Each column of three drums is one Enigma: the top drum copies the left rotor, the middle drum the middle rotor and the bottom drum the right. The top drums spin fastest, slowed right down here. This one is set up to try three rotor orders at once, one per bank, as the real machines did for short menus.

Here's how it uses a menu. The drums are wired together at the back to match the menu, with each Enigma copy set one position further on to match its key press. Then the Bombe makes a guess: "letter E is plugged to A". It follows the menu round, working out what every other letter must be plugged to. If it ever finds a letter that has to be plugged to two different letters at once, that's a contradiction, and the guess is wrong.

And here's the clever bit. A wrong guess doesn't just fail. It sets off a chain of more wrong guesses, one after another, until the wires light up every letter at once. That's an easy thing to detect. If every guess at a rotor position leads to a contradiction, the position is wrong, and the drums move on. Only a position that survives makes the machine stop, so the operators can check it by hand. That turns a search through 17,576 positions into about 20 minutes per rotor order.

It's a bit like a detective who can't say who did it, but can quickly rule people out. Suspect the butler, and the story falls apart within minutes. Suspect the gardener: same. You don't have to prove who did it. You only have to show that nobody else could have.

Welchman then spotted something Turing hadn't. The plugboard swaps in pairs, so if E is plugged to A, then A is plugged to E. His diagonal board wired that fact into the machine, which made every guess spread much further and wrong guesses fail much faster. The first Bombe with one, Agnus, arrived on 8 August 1940. Try it yourself below.

FIG_16 [ A MINI BOMBE ]
Diagonal board
Press Run the Bombe to test every rotor position against the menu.
Fig. 16A small Bombe, working on the real menu from Fig. 14. It only tries the right rotor order (V, II, IV) to save time, and like the real one it assumes only the right-hand rotor moves during the crib. With the diagonal board on, it stops once, at the correct position. Switch it off and run again to see why Welchman's idea mattered.

A stop isn't the answer yet. It gives a rotor position and a few plugboard pairs. The rest of the plugs and the ring settings were worked out by hand, then tested by typing the message into a British Typex cipher machine, altered to work like Enigma. If German came out, that was the day's key, and every message on that network for the whole day could now be read.

The Bombes multiplied. By the end of the war there were about two hundred in Britain. They ran day and night, worked by around two thousand women from the Women's Royal Naval Service, the Wrens. The United States built more than a hundred faster ones of its own. Bletchley grew to nearly 10,000 people, about three quarters of them women.

Part B · 5

Lazy habits and stolen books

Machines did the heavy lifting, but people opened the doors. Enigma operators were tired, cold and busy, and they took shortcuts. Some picked message keys like AAA, or three keys next to each other on the keyboard. At Bletchley these were called cillies, and once you knew an operator's habits, his next key was often easy to guess.

Even the rules meant to stop guessing helped. For a while, the people who wrote the key lists made sure a rotor order never came up twice in a month. They also never plugged two letters that sit next to each other in the alphabet, like A and B. Bletchley noticed both rules. Each one meant fewer settings to try on a given day, so the rules made the job easier, not harder.

Early in 1940, a young mathematician called John Herivel had a hunch. He guessed that some operators set their rings for the day, then barely moved the rotors before picking the first message key. If so, the first message keys of the day should cluster close to the ring settings. The idea, now called the Herivel tip, was right. After the Germans dropped the doubled key in May 1940, the Herivel tip and the cillies were, for a short while, almost the only way in.

The navy was harder. Its operators were better drilled, its message keys were set from separate code books, and it had eight rotors to choose from rather than five. For naval traffic Turing worked out a method called Banburismus, after the town of Banbury where its long paper sheets were printed. It lined up pairs of messages and counted the places where their letters matched. Two messages sent from nearby rotor positions match more often than two random strings would, and that told Turing's team the likely right and middle rotors. The scarce Bombes then only had to try a few orders. Along the way Turing invented a unit for the weight of evidence, the ban.

Captured paperwork helped too. On 9 May 1941 the British forced the U-boat U-110 to the surface, and a boarding party from HMS Bulldog took its Enigma and code books before it sank. Then on 1 February 1942, U-boats switched to a four-rotor Enigma, which Bletchley called Shark, and the Atlantic went dark for most of a year.

That darkness ended because of three men from the destroyer HMS Petard. On 30 October 1942 they swam to the sinking U-559 in the Mediterranean. Lieutenant Tony Fasson and Able Seaman Colin Grazier went inside and passed up code books to Tommy Brown, a young canteen assistant. The submarine sank with Fasson and Grazier still inside. The books included the short weather code that U-boats used, which gave Bletchley cribs for Shark again. By 13 December 1942 it was being read once more.

FIG_17 [ 1932–1945 ]
Fig. 17Thirteen years of codebreaking. Above the line, what the Germans changed. Below it, what the code breakers did about it. The dots on the line are placed to scale by date.
Part B · 6

So did it win the war?

You'll often read that cracking Enigma shortened the war by two years. It's a nice round claim, and historians argue about it a lot.

The figure mostly comes from Harry Hinsley, who worked at Bletchley and later wrote its official history. He judged the war would have been "something like two years longer, perhaps three years longer, possibly four years longer". He also said he thought the Allies would have won anyway. Others put it much lower, at a few months. Guy Hartcup, a historian of wartime science, wrote that it's impossible to put a number of months or years on it at all. And a German post-war study of the U-boat war put its defeat down mainly to Allied radar, not codebreaking.

What nobody disputes is that the decoded messages, which the British called Ultra, were used everywhere. They steered convoys around U-boats in the Atlantic. They showed Rommel's supply problems in North Africa. And before D-Day, they showed that the Germans had swallowed the fake invasion plans. It was a huge advantage. Exactly how huge is a question about a war that didn't happen, and nobody can measure that.

The secret was kept for a remarkably long time. Bertrand wrote about the Polish break in 1973, and the British story only came out properly in 1974. Rejewski lived to see his work recognised, just. He died in Warsaw in 1980. Różycki never did: he drowned in January 1942, when the ship carrying him back to France from Algeria sank in the Mediterranean.

The idea underneath

A shuffle that gives itself away

Step back and the whole story is about shuffles. Every part of Enigma is a permutation: the plugboard, each rotor, the reflector, and the whole machine at each moment. The Germans stacked enough shuffles to make about 1020 keys, and they were right that nobody could try them all.

But nobody had to. Rejewski noticed that some properties of a shuffle survive being shuffled again, like the lengths of its cycles. The people at Bletchley saw that some things can never happen. And a thing that can't happen tells you something. Every time a letter doesn't turn into itself, you learn something. Here's what that looks like over a lot of key presses.

FIG_18 [ NEVER ITSELF ]
Fig. 18A simulated Enigma, with new random settings every few letters, typing at random. Each square counts how often a typed letter (down the side) lit a lamp (along the top). Everything fills in evenly, except the diagonal, which stays empty forever. That empty line is what made cribs work.

How much does one "never" give away? For one letter, not much. A random guess is wrong 25 times out of 26 anyway. But a crib has many letters. The chance that a wrong position for a 16-letter crib dodges every crash is 25/26 multiplied by itself 16 times, which is about 0.53. So each crib throws out about half of the wrong positions for free, before any machine is switched on. That's exactly what you saw in Fig. 13.

The idea → what can't happen tells you something

A good cipher should look completely random. Enigma almost did, but "never the same letter" is a rule, and any rule is a pattern an enemy can lean on. Half the positions for a crib fail on that rule alone.

There's a second lesson too. Back in 1883, a Dutch-born teacher called Auguste Kerckhoffs wrote down some rules for military ciphers. The best known says a cipher shouldn't need to be kept secret, and it should be able to fall into the enemy's hands without causing trouble. Only the key should be secret. This is now called Kerckhoffs's principle.

Enigma, in a way, passed that test. The Poles worked out the wiring, the Allies captured machines, and it still took a daily key to read anything. What failed wasn't the box. It was everything around it: the doubled key, the predictable messages, the lazy settings and the fixed rule that no letter maps to itself.

Hiding

Shuffle the letters, and change the shuffle every key press

→ permutations
Poland

Some things survive a shuffle

→ cycle lengths
Bletchley

Guess a word, then hunt for contradictions

→ cribs & the Bombe
Underneath

What can't happen is information

→ Kerckhoffs's principle

I find it oddly comforting that the machine didn't lose to a bigger machine. It lost to people who were patient, good at maths, and who paid attention to the boring details of how other people actually behaved.

Modern ciphers learned all of these lessons. The one that keeps your bank details safe is public, so anyone can test it. It's designed so that the scrambled output gives away nothing, not even which letters can't appear. And the keys are long enough that no clever shortcut is known. We'll take one apart in the chapter How does the padlock in your browser keep secrets?, and you'll see permutations turn up there too.

So next time you see an Enigma in a museum, look for the three little windows and the finger wheels next to them. Then find the panel of sockets at the front. Picture the trip a single letter takes through it, nine swaps and back to a lamp. And remember that the one lamp it can never light is its own.

For the curious: the numbers behind this chapter

The machine as a formula. Write P for the plugboard, R, M and L for the rotors at the current position, and U for the reflector. One key press, read right to left, is

E = P−1 R−1 M−1 L−1 U L M R P

Because U swaps in pairs and has no letter fixed, E is too. Applying E twice gets you back where you started, which is why the same settings decrypt, and E never sends a letter to itself. (P is its own inverse, so P−1 = P.)

Rotor stepping. A rotor turned on by k steps, with ring setting r, acts like ρs W ρ−s with s = k − r, where W is its wiring and ρ shifts every letter on by one.

The period. The right rotor goes round every 26 presses. The middle rotor visits 25 positions per trip of the left rotor, because the double step skips one. So the pattern repeats after 26 × 25 × 26 = 16,900 presses.

Plugboard settings with ten cables. Choose 20 of the 26 letters and pair them up:

26! ÷ ( 6! × 10! × 210 ) = 150,738,274,937,250
Rotor orders (3 from 5, in order)5 × 4 × 3 = 60
Starting positions263 = 17,576
Plugboard, 10 cables150,738,274,937,250
Total, the usual figure158,962,555,217,826,360,000 ≈ 1.59 × 1020
Ring settings that matter (middle and right)262 = 676
Total with rings≈ 1.07 × 1023

Assumptions: Enigma I with reflector B fixed, three rotors from five, exactly ten cables. The left ring only shifts letters in a way the left rotor's start can copy, so it adds nothing. The middle and right rings change when turnovers happen, so they do add something, but for a short message most of those settings act the same, which is why most books leave them out.

Rejewski's key fact. If A and D are the shuffles at key presses 1 and 4, the first and fourth letters of each indicator are linked by the product AD. Swapping in a plugboard P turns it into P(AD)P, which renames the letters in each cycle but keeps every cycle's length. And because A and D both swap in pairs, the cycles of AD always come in pairs of equal length.

The demos. Every figure here runs the same simulated machine. Its test checks AAAAA → BDZGO (rotors I, II, III, rings and start at A, no plugs) and the full 162-letter wartime-style example from the German Wikipedia article (rotors I, IV, III, rings 16 26 08, ten plugs). The Zygalski sheets in Fig. 12 average about 980 holes each (976 over all 26 sheets), close to the "about a thousand" in the histories. The mini Bombe in Fig. 16 stops at exactly one position with the diagonal board, and at 590 without it.

Key terms

Finished this chapter?