Yeah, he also helped shorten the war which saved a whole lot of lives.
Yeah, he also helped shorten the war which saved a whole lot of lives.
Rommel's Afrika Korps was also defeated by Enigma, because Rommel also refused to believe it was cracked. Enigma pointed out when and where Rommel's supply ships were.
No matter how secure your encryption method is, one should always assume it is cracked. Me, I would have backed it up with one-time pads.
Whereas:
The dropping results made Admiral Dönitz suspicious. Although reassured by the Abwehr, the German Foreign Intelligence, that Enigma was unbreakable, he insisted on improving the security of Enigma. On 1 February 1942 the famous Enigma M4 model with four rotors and new key sheets were introduced.
~ https://www.ciphermachinesandcryptology.com/en/enigmauboats....~ https://uboat.net/technical/enigma_ciphers.htm
There were multiple Enigma variations, based on rotor choice pool sizes, number of fittable rotors, time cycles to changing procedures, etc. Some naval enigma variations were broken, others weren't.
ಠ _ ಠ
Even one-time pads are subject to the efforts used to counter Enigma, such as so-called gardening. I fully agree that layers are better than a single method like Enigma was many times in practice, which is usually all-or-none with no failsafe, at least until later in the war, when Enigma variants started being used in combination with coded messages and code words on top of the Enigma cipher machines themselves, but those efforts were foiled by the dedication and planning of the gardeners’ known-plaintext attacks.
https://en.wikipedia.org/wiki/Gardening_(cryptanalysis)
> In cryptanalysis, gardening is the act of encouraging a target to use known plaintext in an encrypted message, typically by performing some action the target is sure to report. It was a term used during World War II at the British Government Code and Cypher School at Bletchley Park, England, for schemes to entice the Germans to include particular words, which the British called "cribs", in their encrypted messages. This term presumably came from RAF minelaying missions, or "gardening" sorties. "Gardening" was standard RAF slang for sowing mines in rivers, ports and oceans from low heights, possibly because each sea area around the European coasts was given a code-name of flowers or vegetables.
> The technique is claimed to have been most effective against messages produced by the German Navy's Enigma machines. If the Germans had recently swept a particular area for mines, and analysts at Bletchley Park were in need of some cribs, they might (and apparently did on several occasions) request that the area be mined again. This would hopefully evoke encrypted messages from the local command mentioning Minen (German for mines), the location, and perhaps messages also from the headquarters with minesweeping ships to assign to that location, mentioning the same. It worked often enough to try several times.
With 1940s technology, generating a practical one time pad generator would have been an interesting engineering project. I would have simply used a newspaper. Even if your enemy knew you were using Die Zeitung, with the computer technology at the time it would have been tough to brute force which date and which article was used.
The first is that such keys will have all the statistical regularities of the German language, which I believe is problematic, even though I don’t know how one would go about exploiting it.
The second is the matter of how much encrypted text had to be transmitted every day, by the German military as a whole. If it significantly exceeded the daily output of Germany’s newspapers (and I would guess it did) there would seem to be considerable key reuse under this scheme.
For submarines and other units not receiving newspapers daily, there also seems to be a key-distribution issue. I don’t know if there is a better way to guarantee that communication can be maintained through a patrol than to depart with the equivalent of a stack of old newspapers. Is this a problem? I don’t know, but if the allies had figured out the broad outlines of the scheme, I imagine they might be able to do some preparation in anticipation of messages being intercepted.
This discussion started with a proposal to back up Enigma with one-time pads, but harshreality pointed out that OTPs are not vulnerable to anything except compromise of the OTP itself. This has the unstated corollary that if you are using a true OTP system, adding Enigma to the process does nothing to improve security (unless your pre-shared keystream is compromised - and even then, capturing one U-boat's OTP will not compromise any other's communication.)
You then raised the concern of generating keys in sufficient quantity, which is certainly part of the problem (though I suspect that an electro-mechanical solution for that problem was well within the capabilities of contemporary technology, especially as, by then, Konrad Zuse had produced the first digital computer.) If, however, we are restricting our source of keys to the amount of text in a daily newspaper (or even all of the Third Reich's daily newspapers combined), that is something that could be achieved by a corps of dice-rollers, if it came to that, which would avoid one of the other problems of using newspapers: the statistical regularities of newspaper text.
Even then, you still have the problems of key reuse [1] and key distribution, and another which I think might be by far the hardest: training people to use it. Even just considering the submarine fleet, at least one person on each U-boat would have to be trained in properly using the technique. This would delay implementation, and once deployed, even with no mistakes, it would be slow in use.
Alternatively, a machine to do the work might have been developed (together with another to generate physical machine-readable keys), but that itself would have meant considerable delays in implementation.
In view of this, I feel that the measure actually adopted - adding another rotor position to the Enigma machine - was one of the better options (though it would have been even better if the additional rotor were interchangeable with the others.) This took time to implement and was ultimately defeated, but anything other than an OTP system would likely have the latter problem, and all would have had the former.
[1] Maybe not so much of an issue if one is only dealing with submarine communication, given that most of this was with the U-boat High Command in Germany, and assuming that it was of sufficiently low volume for each U-boat to be be given its own unique set of keys for each patrol.
I mentioned also that coordinates and times could be offset by a predetermined amount, and be different for each U-Boot.
As for times, my understanding that they would, at least sometimes, specify them in the form of so many hours after a specific trigger message was received. This seems to require the U-boat to be surfaced (or maybe just at periscope depth?) from the start of the window for this message until it was received.
None of this addresses the training issue from earlier. The thing is, if you are thinking of using a newspaper-based scheme only for U-boats, you might as well go the extra distance to implement a true OTP system, which seems feasible at that scale and which would turn the use of Enigma in series into an academic exercise.
BTW, I've used dice rolls to generate passwords, but the dice would always fall off my desk and roll into an inaccessible corner, and I soon tired of that. It also only worked for 6 digits! So I switched to a real RNG.
As for key interdiction, it would have to be at massive scale, as having a handful of random keys does not enable industrial-scale decryption, which is what the allies needed (and had, some of the time) for signals intelligence to be useful against U-boats. In contrast, the leaking of one date would compromise the entirety of the communications conducted under it (i.e., at least those for one U-boat for the duration of the patrol), especially given that German newspapers were readily available in neutral and occupied countries. OTPs are, in fact, way more resistant to espionage than your newspaper scheme.
The failure of the location-shifting scheme (as mentioned in my previous post) to stop the allies interdicting rendezvous, despite its periodic changes, also suggests that one date per patrol is not going to be good enough.
We have reached the point where the alleged superiority of your newspaper scheme hangs on the tendency of dice to roll off your desk!
In the book they used bingo style mechanical RNGs, by hand.
This fact proved by Friedman in 1918 has become widely known a few years later, in 1926, when Gilbert Sandford Vernam has published an article "Cipher Printing Telegraph Systems For Secret Wire and Radio Telegraphic Communications" in a journal.
While Vernam mentioned the help from Friedman, he gave no details and the works written by Friedman for the education of American cryptographers have remained classified for many decades.
Because of this, secure one-time pads have been referred frequently as the Vernam cipher, but this is wrong, as he is not its inventor, but only the first who has mentioned it in the non-classified literature.
Vernam (as a Bell Labs engineer) had a very important contribution to cryptography, but of a different kind. He has invented enciphering by modulo-2 sum (a.k.a. XOR), which is cheaper to implement in hardware than the integer addition used previously.
However, in the fullness of time and with research into and with declassification of wartime intelligence thereof since the war of the now-known semi-regular failures to key and operate the Enigma machine properly, the hypothetical serially encoded (Enigma + one-time pad) materials would possibly be able to be attacked due to operator errors/failures of key rotation independently of and/or combined with known-plaintext attacks, but I will defer to you on the actual cryptanalysis and mathematical modeling.
I humbly admit that am not well-versed in this field, and I am not anything other than a fan of you and your work in the computing field, as it is mostly over my head.
Another simple method would be to add an offset to the "rendevous at XX longitude and YY latitude" coordinates and time.
All of this is to say that I’m not sure that inconsistencies couldn’t be intentionally introduced in even the printed material to throw off encryption attempts if the source of the one-time pad were to have leaked. Knowing what is public knowledge regarding Crypto AG being compromised, I’m not willing to bet that a newspaper would be a safe bet for source material. A King James Version Bible, perhaps.
On the other hand, you have more fingers, and the long arm of the law casts an even longer shadow in wartime. Multi-armed bandits exist.
In contrast they attributed getting attacked after sending in a position report to radio triangulation equipment allies had, called huff-duff.
And in most cases huff-duff was the reason they were attacked. Bletchley Park was too slow to provide an actionable attack vector off a position report. Instead ultra was used to route convoys around the u-boats. They experienced ultra as empty ocean they they hoped they would find a convoy.
The one exception was the "milk cows". These were resupply subs that were to rendezvous with u-boats in the open ocean. Dönitz would send orders for a rendezvous, bletchley would decrypt and send orders to a "hunter killer" group consisting of an aircraft carrier and destroyers to attract the two subs while resupplying.
Rommel attributed the attacks on his secret convoys to spies.