Click for homepage
OTP
  
OTT
One-time tape cipher machines · mixers

One-Time Tape, abbreviated OTT, is a general expression for teleprinter cipher machines that are based on the principle of the One-Time Pad (OTP), where the key stream is distributed on perforated paper tape, rather than printed on paper as a pad. The system can be regarded as a digital implementation of the OTP. When correctly applied, a message encrypted with an OTT is unbreakable, although in practice some OTT cipher machines exhibited TEMPEST problems.

Most (but not all) OTT cipher machines use a 5-bit digital code such as the ITA-2 standard (Bau­dot) or MTK-2. Random characters (e.g. from a noise generator) are recorded onto a punched paper tape that is used as the KEY. Only one du­pli­cate of this KEY is made, so that both sides of a communication line have an identical KEY.

The KEY tape is then com­bi­ned, character-by-character, with the plaintext by means of a XOR-ope­ra­tions (modulo-2 addi­tion). The com­bining XOR function was patented by Gilbert Vernam in 1918, and is known as the Vernam Cipher.
  

The advantage of adding the KEY to the plaintext by means of an XOR-operation in order to ob­tain the ciphertext, is that the same KEY can be be XOR-ed with the ciphertext in order to obtain the original plaintext. This makes the cipher symmetrical. Bell Labs engineer Claude Shannon proved during WWII that, when correctly implemented, the Vernam Cipher is unbreakable.

The above process is also known as mixing, which is why OTT cipher machines are also known as mixers. A good example of a mixer is the Norwegian ETCRRM, which was used from 1963 onward on the Washington-Moscow teleprinter hotline. It was replaced in 1980 by the Siemens M-190. It should be noted that an unkeyed OTT cipher machine is usually an unclassified device. As soon as it is loaded with a KEY tape — i.e. it is keyed — it is classified to the level of the KEY tape.

The use of an OTT cipher system is 100% secure when all of the following conditions are met:

  1. The keytapes contain truly random characters (i.e. noise)
  2. The keytape has a least the same length as the plaintext message
  3. Only two copies of the keytape exist (the original and a duplicate)
  4. The keytape is used only once (hence the name one-time tape)
  5. Both copies of the keytape are destroyed immediately after use
  6. Care is taken to avoid manipulation and espionage during key distribution
  7. Sufficient measures are taken against compromising emanations (TEMPEST)
Mixers on this website
British/Canadian Telekrypton (not a real OTT), built in the USA (1926)
USSR M-100 one-time tape cipher machine (1938)
Russian M-105 (AGAT) mixer machine (1968)
DUDEK StG-1 (T-352 / T-353) one-time tape cipher machine developed in Poland (1966)
British/Canadian one-time tape cipher machine used during and after WWII (1943)
British one-time tape cipher machine compatible with Rockex (1962)
British 5-UCO (BID/30) OTT cipher machine (1943)
BID/570 (Derby) one-time tape cipher machine - British version of ETCRRM (1959)
PTT Colex (predecessor of Ecolex)
Ecolex I, developed by PTT, manufactured by Philips Usfa (1950)
Ecolex I Mark 2, developed by PTT, never produced in quantity (1953)
Ecolex II, developed by PTT, manufactured by Philips Usfa (1955)
Ecolex III (or Ecolex IIB), the synchronised variant of the Ecolex II (1959)
Philips Ecolex IV one-time tape teleprinter cipher machine (1963)
ETCRRM mixer machine used on the Washington-Moscow hotline (1954)
Lorenz Mixer Mi-544 one-time tape cipher machine (1956)
The Siemens T-43 one-time tape cipher machine (1943)
Siemens T-37i CA one-time tape cipher machine (1956)
Siemens Schlüsselgerät D one-time tape cipher machine (1957)
Siemens M-190 OTT cipher machine, used on the Washington-Moscow hotline (1962)
Hagelin C-446/RT, the OTP (OTT) version of the C-446 (1946)
OTP/OTT version of the Hagelin CX-52 (1952)
Hagelin TC-52 (1952)
Crypto AG (Hagelin) ULES-64 one-time tape cipher machine (1966)
SELMA OKA-150, one-time tape cipher machine (1960)
ACEC TP-845 one-time-tape cipher machine (1970)
Mils Elektronik TT-360 OTT teleprinter cipher machine (1972)
Mils Elektronik ME-620 one-time tape cipher machine (1975)
Mils Elektronik ME-680 one-time tape cipher machine with floppy drive (1982)
Mils Elektronik ME-640 one-time tape cipher machine with key generator (1986)
 List of known mixers


Keytape generators
Random keytape generator developed by Atheneum Stiftung (1953)
Atheneum
Hazardo
Reichert Würfelgenerator - Random Key Tape Perforator (1953)
Reichert
Würfel
HELL H-502 pseudo-random generator for production of keytapes (1955~)
Hell
H-502
Crypto AG (Hagelin) ZF-57 Zeichen-Generator - Random keytape generator (1957)
Crypto AG
ZG-57
Erolet random-number geerator for the creation of keytapes
STK (Thales) KTP-3 keytape generator (1959)
Reichert STG-5001 random number generator for keytapes (1960)
Reichert
STG-5001
Reichert STG-5002 random number generator for keytapes (1961)
Reichert
STG-5002
Reichert STG-5003 random number generator for keytapes (1962)
Reichert
STG-5003
Reichert Elektronik 5224 Random Key Tape Perforator (1963)
Mils A-6723 family of random keytape generators (1967)
Mils ME-600 keytape generator (1992)
Please note that not all items above are selectable. This is the case if no further information is currently available.


Related items
The unbreakable One-Time Pad (OTP)
OTP
KD-100 key tape disintegrator
UNCLASSIFIED — It is a common misunderstanding that mixers, like most other cipher machines, are classified items. This is not the case. The operating principle of a mixer – a bitwise XOR-operation – is not secret at all. It is a common mathematical modulo-2 addition. Consequently, most mixer machines were unclassified, although their circuit diagrams and user manuals may have been restricted at the time. With machines of this class, it is the keytape that protects the secret. A machine loaded with a keytape, is classified to the level of the keytape.
Principle
OTT uses properties of digital telegraphy, also known as Telex, Teletype, 1 Teleprinter or Tele­typewriter. Messages can be stored on perforated tape, where the holes of each column re­pre­sent a character. A column was usually 5 holes high, but other data formats were also used. The most common formats, like ITA-2 and MTK-2, use 5 holes or channels. In modern ter­mi­no­logy, these holes would be called bits (0 or 1). A '1' represents a hole and a '0' is the absence of a hole.

Example of a 5-level punched paper tape

The channels or units of a perforated tape are usually numbered 1-5, from top to bottom, as shown in the diagram above. In modern terminology these channels would be numbered as digital bits in the order 0-4. In the example above, the perforated tape moves through a reader from right to left, whilst the holes are sampled vertically, one character at a time. This means that the tape is read from left to right. The smaller holes in the third row are the sprocket holes. They are used for transport of the tape. Sometimes they also provided the clock signal for the reader.

In the diagrams below, the principle of the Vernam Cipher is explained by using a message stored on a perforated paper tape. Suppose we want to transmit the word
HELLO
which is stored on the plain­text tape at the left. We also have a pre-recorded key tape, with a series of random cha­rac­ters; in this case the sequence
AXHJB
. The contents of the plaintext tape are now XOR-ed with the contents of the key tape. The result (
KMIVE
) is shown here as the ciphertext tape:

Mixing the plaintext with the key

Now let us see what happens if we repeat this operation on the resulting ciphertext tape with the letters '
KMIVE
'. In the illustration below, the ciphertext tape is on the left. It is XOR-ed with a copy of the original key tape (
AXHJB
), which results in the original plaintext: '
HELLO
'.

Mixing the ciphertext with the key

This process of applying the XOR-operation to text and key is often called mixing, and the cipher machines that use the Vernam principle, are therefore known as mixers. In the days when teleprinters were in widespread use, technicians were often so experienced that they could read a text directly from a paper tape, simply by looking at the holes and reading the bit patterns.

Mixing of ciphertext and key by holding the two tapes against the light
Visually mixing of the ciphertext with the key

Maintenance engineers were able to do the same with the tapes of OTT cipher machines. By taking a cipher­text tape, overlaying it with a keytape and holding it against a bright light source, they were often able to 'read' the plaintext directly. This is illustrated in the drawing above, in which each half-transparent hole (either red or bue) should be interpreted as as a binary '1'. The same can be done when combining the ciphertext tape with the keytape, as shown below.

Mixing of plaintext and key by holding the two tapes against the light
Visially mixing the plaintext with the key

  1. Although 'Teletype' is actually a brand name of the Teletype Corporation, it has become a generic expression for digital 5-bit telegraphy. Even in modern computer operating systems, a terminal connected to the serial port is known as a 'TTY', which is short for TeleTYpe.
Invention
Many companies and countries claim the invention of the one-time tape cipher machine. The accounts differ per country. Although the Philips Ecolex was definitely not the first machine in this class, its inventor was payed for his patents for many years. STK (now: Thales) claims that it was a Norwegian invention, but their patent of 1952 1 is predated by a Siemens patent of 1921 [3].

Furthermore, the Siemens T-43, the British 5-UCO and the British-Canadian Rockex, were all developed and built during WWII, in 1943, well before the machines mentioned above. So, who is the actual inventor and who built the first OTT machine? To answer this question, we must first look at the definition of a one-time tape cipher machine. It basically consists of two parts:

  1. Mixer
  2. Random tape
The mixer was invented in 1918 by Gilbert Vernam in the US, whilst working at Bell Telephone Laboratories (BTL). In US Patent 1,310,719 he describes a cipher system in which a plaintext cha­rac­ter is mixed with a character from a key­tape, although he does not claim that the key­tape has (at least) the same length as the plaintext message and that it contains fully random characters. According the NSA, Vernam's invention is perhaps the most important one in the history of cryp­to­graphy [5]. His principle of the mixer (XOR, modulo-2) became known as the Vernam Cipher.

 More about the Vernam Cipher


The One-Time Pad (OTP), on which the OTT is based, was first described in 1882 by US banker Frank Miller [6][7]. It was reportedly re-invented in 1917 by Joseph Mauborgne [1], but we are unable to put an exact date on it. The closest timeframe can be found in David Kahn's book The Codebreakers [8 p.6], in which he dates the re-invention to 'during World War I' (1914-1918), when Mauborgne was Chief Signal Officer of the Signal Corps Engineering and Research Division of the US Army. So, it is entirely possible that this happened in 1917.

 More about the one-time pad


Shortly after Vernam's invention of the mixer, Joseph Mauborgne recognised that if the key­tape would contain fully random characters, the cipher would be un­breakable [8 p.397-388]. We may there­fore assume that the OTT was invented by Vernam and Mauborgne in late 1918.

Nevertheless, the first cipher machine that used the Vernam Cipher — the Telekrypton of 1926 — did not use a one-time random keytape. Instead it used two looped tapes of a different (finite) length [8 p.397]. This means that Te­le­krypton was not the first OTT cipher machine, and that therefore, based on the currently available in­for­mation, the Russian M-100 from 1938, should be re­cog­nised as the first OTT cipher machine that was produced in quantity.

  1. Although this patent is frequenty mentioned in literature, for example in [2], we have not been able to find it. If anyone has access to this patent, please contact us.
Inventors
YearEventInventor
1882Invention of the one-time pad (OTP)Frank Miller
1917Re-invention of the OTPJoseph Mauborgne
1918Invention of the mixerGilbert Vernam
1918Invention of the OTT cipher machineGilbert Vernam, Joseph Mauborgne
1938First OTT cipher machineM-100 (USSR)
Order of events
YearEventCountryRemark
1882 Invention of the One-Time Pad (OTP) USA Frank Miller
1917 Re-invention of the one-time pad USA Vernam, Mauborgne
1918 Patent US 1,310,719 (Vernam) [3] USA Invention of Vernam Cipher
1918Randomness added to Vernam CipherUSAInvention of the OTT
1921 Patent DE 371,087 (Siemens) [4] Germany  
1926 Telekrypton UK/Canada Not a real OTT
1938 M-100 USSR First OTT machine
1943 T-43 Germany  
1943 Rockex UK  
1943 5-UCO UK  
1946 Colex Netherlands  
1950 Ecolex I Netherlands  
1953 ETCRRM Norway First Hotline
1954 Ecolex II Netherlands  
 More OTT cipher machines




OTT tapes
Randomness
When creating keytapes, it is of the utmost importance that the tape contains uniformly dis­tri­bu­ted random characters, with no bias or repetition. This means that they keytape may not contain a random text in a particular language, as that would make the cipher solvable. The best random tapes were created with a white noise source, such as radioactive decay or thermal noise ge­ne­ra­ted by a diode. In all cases, test equipment had to be present to continuously check the random­ness of the generated data, and raise an alarm if was no longer within reasonable boundaries.

In practice however, several manufacturers of keytape generators used mechanical methods for creating a pseudo-random key sequence. Manufacturer Hell, for example, used five looped perforated tape strings of different length, in order to generate a key with a long cipher period. Although the tape strings themselves contained data with a uniform distribution, the repetitive nature of the keystream made it deterministic and therefore solvable.

Even when a real noise source was used, the situation was often not ideal. During the latter part of World War II (WWII) and the beginning of the Cold War, keytapes for the British OTT ma­chines — 5-UCO, Rockex and WIM — were generated in a central facility. At some point, engi­neers no­ticed that the random keystream had a slight bias. This was thought to be acceptable for Rockex, but was totally unacceptable for the top-level 5-UCO that was used by the high-command [9].

Generation
Various machines were developed for the pro­duc­tion of OTT key tapes. Some machines used mechanical methods to create a pseudo-random key stream, whilst others produced truly random characters generated by a white noise source.

In most cases, the devices had purpose-built tape punchers that were able to punch two key tapes simultaneously, to ensure that they were identical. Most generators also had devices that could check the randomness of the key stream.

 List of keytape generators

  

Distribution
A major problem with the use of OTT systems, is the distribution of the key tapes. As each tape can only be used once, and must be at least as long as the message itself, an enourmous stock of fresh tapes is required, especially on busy military circuits far away from the homeland.

For diplomatic use (embassies, etc.), large quan­ti­ties of tapes had to be shipped by diplomatic bag. Although such shipments are protected under international law, there is always a risk of interception and tampering, especially in high-risk or hostile countries.
  

Destruction
One of the conditions for proper use of an OTT system, is that the keytapes are destroyed im­me­di­a­tely after use. This is done to prevent re­construction of the plain­text by a malicious party from (partly) recovered keytapes.

To ensure that the keytape could not be used again, some OTT cipher machines had a built-in knife that cut the keytape in half upon leaving the tape reader. For proper security however, the tapes had to be destroyed completely, e.g. with a special device, such as the KD-100 shown in the image on the right. It produces paper powder.

 More information

  




TEMPEST problems
Even when the regular conditions for use of a one-time pad (OTP) are met, there is still a risk of losing intelligence when the equipment emanates compromising signals. In modern terminology this is known as side channel leakage. Within NATO the phenomenon is known as TEMPEST. There are various types of compromising emanations, such as acoustic, optical, electrical and via RF energy (radio). The effect was first discovered at Bell Labs during WWII in 1943. It was discovered that teleprinters could cause glitches (spikes) that could be picked up at a considerable distance.

The first problems with OTT cipher machines (mixers) were discovered in the late 1950s and early 1960s. It prompted the manufacturers to add shielding and filtering to the design. In some cases, multiple measures had to be taken to avoid potentional leakage of intelligence-bearing signals.

 More about TEMPEST


Known mixers
Below is a non-exhaustive list of known one-time tape cipher machines. If you come across an OTT machine that is not listed here, please let us know.

YearModelBitsAlphabetManufactuerCountry
1926 Telekrypton 5 ITA-2 Western Union UK/Canada
1938 M-100 5 MTK-2 ? USSR
1943 Rockex 6 ITA-2 HMGCC UK
1943 5-UCO 5 ITA-2 HMGCC UK
1943 T-43 5 ITA-2 Siemens Germany
1946 Colex 5 ITA-2 PTT Netherlands
1946 C-446/RT 5 ITA-2 Hagelin Sweden
1950 Ecolex I 5 ITA-2 Philips Netherlands
1950CH-3-A5ITA-2OlivettiItaly
1952 CX-52/RT 5 ITA-2 Hagelin Switzerland
1952 TC-52 5 ITA-2 Hagelin Sweden
1953 ETCRRM 5 ITA-2 STK Norway
1954 Ecolex II 5 ITA-2 Philips Netherlands
1955TC-555ITA-2HagelinSweden
1956 Mi544 5 ITA-2 Lorenz Germany
1956 T-37i CA 5 ITA-2 Siemens Germany
1956UG-20225ITA-2?Israel
1957 Schlüsselgerät D 5 ITA-2 Siemens Germany
1959 Ecolex III 5 ITA-2 Philips Netherlands
1959RTE-595ITA-2HagelinSwitzerland
1959 Derby BID/570 5 ITA-2 STK Norway
1960 Selma 5 ITA-2 STK Norway
1962 Noreen 6 ITA-2 HMGCC UK
1962 M-190 5 ITA-2 Siemens Germany
1963 Ecolex IV 5 ITA-2 Philips Netherlands
1963 TCE-160 5 ITA-2 STK Norway
1966 ULES-64 5 ITA-2 Hagelin Switzerland
1967 T-352 Dudek 5 ITA-2 Teletra Poland
1968 M-105 11 ? ? USSR
1970TP-8455ITA-2ACECBelgium
1972 TT-360 5 ITA-2 Mils Austria
1975 ME-620 5 ITA-2 Mils Austria
1982 ME-840 5 ITA-2 Mils Austria
1986 ME-640 5 ITA-2 Mils Austria
Specifications
References
  1. Wikipedia, One-time pad
    Accessed January 2013.

  2. Norwegian National Security Authority (NSM), Årsmelding 2008
    NSM Annual Report 2008 (Norwegian). Noen kryptosuksesser. p. 15.

  3. US Patent 1,310,719, Secret Signalling System
    Filed 13 September 1918.

  4. German Patent DE371087
    Patent describing the principle of a mixer machines. Filed: 10 July 1921.

  5. Melville Klein, Securing Record Communications. The TSEC/KW-26
    NSA, CCH, 2003. Updated 19 March 2004.

  6. Telegraphic Code to Insure Privacy and Secrecy in the Transmission of Telegrams
    Frank Miller, 1982. Via WikiSource.

  7. Steven M. Bellovin, Frank Miller: Inventor of the One-Time Pad
    CUCS-009-11. Columbia University, Department of Computer Science.
    Cryptologia 35(3), 12 July 2011. p. 203-222.

  8. David Kahn, The Codebreakers
    Macmillian, New York (USA). First printing, 1967.

  9. John Bowen (G8DET), Remembering the BID/30 (5-UCO)
    Personal correspondence, 7 July 2019.
Further information
Any links shown in red are currently unavailable. If you like the information on this website, why not make a donation?
© Crypto Museum. Created: Saturday 08 September 2012. Last changed: Sunday, 23 August 2026 - 20:55 CET.
Click for homepage