Click for homepage
OTP
  
OTT
One-time tape cipher machines · mixers

One-Time Tape, abbreviated OTT, is a general expression for teleprinter cipher machines that are based on the principle of the One-Time Pad (OTP), where the key stream is distributed on perforated paper tape, rather than printed on paper as a pad. The system can be regarded as a digital implementation of the OTP. When correctly applied, a message encrypted with an OTT is unbreakable, although in practice some OTT cipher machines exhibited TEMPEST problems.

Most (but not all) OTT cipher machines use a 5-bit digital code such as the ITA-2 standard (Bau­dot) or MTK-2. Random characters (e.g. from a noise generator) are recorded onto perforated tape, which is then used as the KEY. Only one du­pli­cate of this KEY is made, so that both sides of a communication line have an identical KEY.

The KEY tape is then com­bi­ned, character-by-character, with the plaintext by means of a XOR-ope­ra­tions (modulo-2 addi­tion). The com­bining XOR function was patented by Gilbert Vernam in 1918, and is known as the Vernam Cipher.
  

The advantage of adding the KEY to the plaintext by means of an XOR-operation in order to ob­tain the ciphertext, is that the same KEY can be be XOR-ed with the ciphertext in order to obtain the original plaintext. This makes the cipher symmetrical. Bell Labs engineer Claude Shannon proved during WWII that, when correctly implemented, the Vernam-based OTT is unbreakable.

The above process is also known as mixing, which is why OTT cipher machines are also known as mixers. A good example of a mixer is the Norwegian ETCRRM, which was used from 1963 onward on the Washington-Moscow teleprinter hotline. It was replaced in 1980 by the Siemens M-190. It should be noted that an unkeyed OTT cipher machine is usually an unclassified device. As soon as it is loaded with a KEY tape — i.e. it is keyed — it is classified to the level of the KEY tape.

The use of an OTT cipher system is 100% secure when all of the following conditions are met:

  1. The keytapes contain truly random characters (i.e. noise)
  2. The keytape has a least the same length as the plaintext message
  3. Only two copies of the keytape exist (the original and a duplicate)
  4. The keytape is used only once (hence the name one-time tape)
  5. Both copies of the keytape are destroyed immediately after use
  6. Care is taken to avoid manipulation and espionage during key distribution
  7. Sufficient measures are taken against compromising emanations (TEMPEST)
 Advantages Disadvantages
100% secure (see above)Key distribution
Infinite confidentialityNo authentication
Same key at both ends  
Mixers on this website
British/Canadian Telekrypton (not a real OTT), built in the USA (1926)
USSR M-100 one-time tape cipher machine (1938)
Russian M-105 (AGAT) mixer machine (1968)
DUDEK StG-1 (T-352 / T-353) one-time tape cipher machine developed in Poland (1966)
British/Canadian one-time tape cipher machine used during and after WWII (1943)
British one-time tape cipher machine compatible with Rockex (1962)
British 5-UCO (BID/30) OTT cipher machine (1943)
BID/570 (Derby) one-time tape cipher machine - British version of ETCRRM (1959)
PTT Colex, relay based one-time tape cipher machine (1946)
Ecolex I, developed by PTT, manufactured by Philips Usfa (1950)
Ecolex I Mark 2, developed by PTT, never produced in quantity (1953)
Ecolex II, developed by PTT, manufactured by Philips Usfa (1955)
Ecolex III (or Ecolex IIB), the synchronised variant of the Ecolex II (1959)
Philips Ecolex IV one-time tape teleprinter cipher machine (1963)
ETCRRM mixer machine used on the Washington-Moscow hotline (1954)
Lorenz Mixer Mi-544 one-time tape cipher machine (1956)
The Siemens T-43 one-time tape cipher machine (1943)
Siemens T-37i CA one-time tape cipher machine (1956)
Siemens Schlüsselgerät D one-time tape cipher machine (1957)
Siemens M-190 OTT cipher machine, used on the Washington-Moscow hotline (1962)
Hagelin C-446/RT, the OTP (OTT) version of the C-446 (1946)
OTP/OTT version of the Hagelin CX-52 (1952)
Hagelin TC-52 (1952)
Crypto AG (Hagelin) ULES-64 one-time tape cipher machine (1966)
SELMA OKA-150, one-time tape cipher machine (1960)
ACEC TP-845 one-time-tape cipher machine (1970)
Mils Elektronik TT-360 OTT teleprinter cipher machine (1972)
Mils Elektronik ME-620 one-time tape cipher machine (1975)
Mils Elektronik ME-680 one-time tape cipher machine with floppy drive (1982)
Mils Elektronik ME-640 one-time tape cipher machine with key generator (1986)
 List of known mixers


Keytape generators
Random keytape generator developed by Atheneum Stiftung (1953)
Atheneum
Hazardo
Reichert Würfelgenerator - Random Key Tape Perforator (1953)
Reichert
Würfel
HELL H-502 pseudo-random generator for production of keytapes (1955~)
Hell
H-502
Erolet random-number geerator for the creation of keytapes (1955)
Crypto AG (Hagelin) ZF-57 Zeichen-Generator - Random keytape generator (1957)
Crypto AG
ZG-57
STK (Thales) KTP-3 keytape generator (1959)
Reichert STG-5001 random number generator for keytapes (1960)
Reichert
STG-5001
Reichert STG-5002 random number generator for keytapes (1961)
Reichert
STG-5002
Reichert STG-5003 random number generator for keytapes (1962)
Reichert
STG-5003
Reichert Elektronik 5224 Random Key Tape Perforator (1963)
Mils A-6723 family of random keytape generators (1967)
Mils ME-600 keytape generator (1992)
Please note that not all items above are selectable. This is the case if no further information is currently available.


Related items
The unbreakable One-Time Pad (OTP)
OTP
KD-100 key tape disintegrator
UNCLASSIFIED — It is a common misunderstanding that mixers, like most other cipher machines, are classified items. This is not the case. The operating principle of a mixer – a bitwise XOR-operation – is not secret at all. It is a common mathematical modulo-2 addition. Consequently, most mixer machines were unclassified, although their circuit diagrams and user manuals may have been restricted at the time. With machines of this class, it is the keytape that protects the secret. A machine loaded with a keytape, is classified to the level of the keytape.
Principle
OTT uses properties of digital telegraphy, also known as Telex, Teletype, 1 Teleprinter or Tele­typewriter. Messages can be stored on perforated tape, where the holes of each column re­pre­sent a character. A column was usually 5 holes high, but other data formats were also used. The most common formats, like ITA-2 and MTK-2, use 5 holes or channels. In modern ter­mi­no­logy, these holes would be called bits (0 or 1). A '1' represents a hole and a '0' is the absence of a hole.

Example of a 5-level punched paper tape

The channels or units of a perforated tape are usually numbered 1-5, from top to bottom, as shown in the diagram above. In modern terminology these channels would be numbered as digital bits in the order 0-4. In the example above, the perforated tape moves through a reader from right to left, whilst the holes are sampled vertically, one character at a time. This means that the tape is read from left to right. The smaller holes in the third row are the sprocket holes. They are used for transport of the tape. Sometimes they also provided the clock signal for the reader.

In the diagrams below, the principle of the Vernam Cipher is explained by using a message stored on a perforated paper tape. Suppose we want to transmit the word
HELLO
which is stored on the plain­text tape at the left. We also have a pre-recorded key tape, with a series of random cha­rac­ters; in this case the sequence
AXHJB
. The contents of the plaintext tape are now XOR-ed with the contents of the key tape. The result (
KMIVE
) is shown here as the ciphertext tape:

Mixing the plaintext with the key

Now let us see what happens if we repeat this operation on the resulting ciphertext tape with the letters '
KMIVE
'. In the illustration below, the ciphertext tape is on the left. It is XOR-ed with a copy of the original key tape (
AXHJB
), which results in the original plaintext: '
HELLO
'.

Mixing the ciphertext with the key

This process of applying the XOR-operation to text and key is often called mixing, and the cipher machines that use the Vernam principle, are therefore known as mixers. In the days when teleprinters were in widespread use, technicians were often so experienced that they could read a text directly from a paper tape, simply by looking at the holes and reading the bit patterns.

Mixing of ciphertext and key by holding the two tapes against the light
Visually mixing of the ciphertext with the key

Maintenance engineers were able to do the same with the tapes of OTT cipher machines. By taking a cipher­text tape, overlaying it with a keytape and holding it against a bright light source, they were often able to 'read' the plaintext directly. This is illustrated in the drawing above, in which each half-transparent hole (either red or bue) should be interpreted as as a binary '1'. The same can be done when combining the ciphertext tape with the keytape, as shown below.

Mixing of plaintext and key by holding the two tapes against the light
Visially mixing the plaintext with the key

  1. Although 'Teletype' is actually a brand name of the Teletype Corporation, it has become a generic expression for digital 5-bit telegraphy. Even in modern computer operating systems, a terminal connected to the serial port is known as a 'TTY', which is short for TeleTYpe.
Invention
Many companies and countries claim the invention of the one-time tape cipher machine. The accounts differ per country. Although the Philips Ecolex was definitely not the first machine in this class, its inventor was payed for his patents for many years. STK (now: Thales) claims that it was a Norwegian invention, but their patent of 1952 1 is predated by a Siemens patent of 1921 [3].

Furthermore, the Siemens T-43, the British 5-UCO and the British-Canadian Rockex, were all developed and built during WWII, in 1943, well before the machines mentioned above. So, who is the actual inventor and who built the first OTT machine? To answer this question, we must first look at the definition of a one-time tape cipher machine. It basically consists of two parts:

  1. Mixer
  2. Random tape
The mixer was invented in 1918 by Gilbert Vernam in the US, whilst working at Bell Telephone Laboratories (BTL). In US Patent 1,310,719 he describes a cipher system in which a plaintext cha­rac­ter is mixed with a character from a key­tape, although he does not claim that the key­tape has (at least) the same length as the plaintext message and that it contains fully random characters. According the NSA, Vernam's invention is perhaps the most important one in the history of cryp­to­graphy [5]. His principle of the mixer (XOR, modulo-2) became known as the Vernam Cipher.

 More about the Vernam Cipher


The One-Time Pad (OTP), on which the OTT is based, was first described in 1882 by US banker Frank Miller [6][7]. It was reportedly re-invented in 1917 by Joseph Mauborgne [1], but we are unable to put an exact date on it. The closest timeframe can be found in David Kahn's book The Codebreakers [8 p.6], in which he dates the re-invention to 'during World War I' (1914-1918), when Mauborgne was Chief Signal Officer of the Signal Corps Engineering and Research Division of the US Army. So, it is entirely possible that this happened in 1917.

 More about the one-time pad


Shortly after Vernam's invention of the mixer, Joseph Mauborgne recognised that if the key­tape would contain fully random characters, the cipher would be un­breakable [8 p.397-388]. We may there­fore assume that the OTT was invented by Vernam and Mauborgne in late 1918.

Nevertheless, the first cipher machine that used the Vernam Cipher — the Telekrypton of 1926 — did not use a one-time random keytape. Instead it used two looped tapes of a different (finite) length [8 p.397]. This means that Te­le­krypton was not the first OTT cipher machine, and that therefore, based on the currently available in­for­mation, the Russian M-100 from 1938, should be re­cog­nised as the first OTT cipher machine that was produced in quantity.

  1. Although this patent is frequenty mentioned in literature, for example in [2], we have not been able to find it. If anyone has access to this patent, please contact us.
Inventors
YearEventInventor
1882Invention of the one-time pad (OTP)Frank Miller
1917Re-invention of the OTPJoseph Mauborgne
1918Invention of the mixerGilbert Vernam
1918Invention of the OTT cipher machineGilbert Vernam, Joseph Mauborgne
1938First OTT cipher machineM-100 (USSR)
Order of events
YearEventCountryRemark
1882 Invention of the One-Time Pad (OTP) USA Frank Miller
1917 Re-invention of the one-time pad USA Vernam, Mauborgne
1918 Patent US 1,310,719 (Vernam) [3] USA Invention of Vernam Cipher
1918Randomness added to Vernam CipherUSAInvention of the OTT
1921 Patent DE 371,087 (Siemens) [4] Germany  
1926 Telekrypton UK/Canada Not a real OTT
1938 M-100 USSR First OTT machine
1943 T-43 Germany  
1943 Rockex UK  
1943 5-UCO UK  
1946 Colex Netherlands  
1950 Ecolex I Netherlands  
1953 ETCRRM Norway First Hotline
1954 Ecolex II Netherlands  
 More OTT cipher machines




OTT tapes
Randomness
When creating keytapes, it is of the utmost importance that the tape contains uniformly dis­tri­bu­ted random characters, with no bias or repetition. This means that they keytape may not contain a random text in a particular language, as that would make the cipher solvable. The best random tapes were created with a white noise source, such as radioactive decay or thermal noise ge­ne­ra­ted by a diode. In all cases, test equipment had to be present to continuously check the random­ness of the generated data, and raise an alarm if was no longer within reasonable boundaries.

In practice however, several manufacturers of keytape generators used mechanical methods for creating a pseudo-random key sequence. Manufacturer Hell, for example, used five looped perforated tape strings of different length, in order to generate a key with a long cipher period. Although the tape strings themselves contained data with a uniform distribution, the repetitive nature of the keystream made it deterministic and therefore solvable.

Even when a real noise source was used, the situation was often not ideal. During the latter part of World War II (WWII) and the beginning of the Cold War, keytapes for the British OTT ma­chines — 5-UCO, Rockex and WIM — were generated in a central facility. At some point, engi­neers no­ticed that the random keystream had a slight bias. This was thought to be acceptable for Rockex, but was totally unacceptable for the top-level 5-UCO that was used by the high-command [9].

Generation
Various machines were developed for the pro­duc­tion of OTT key tapes. Some machines used mechanical methods to create a pseudo-random key stream, whilst others produced truly random characters generated by a white noise source.

In most cases, the devices had purpose-built tape punchers that were able to punch two key tapes simultaneously, to ensure that they were identical. Most generators also had devices that could check the randomness of the key stream.

 List of keytape generators

  

Distribution
A major problem with the use of OTT systems, is the distribution of the key tapes. As each tape can only be used once, and must be at least as long as the message itself, an enourmous stock of fresh tapes is required, especially on busy military circuits far away from the homeland.

For diplomatic use (embassies, etc.), large quan­ti­ties of tapes had to be shipped by diplomatic bag. Although such shipments are protected under international law, there is always a risk of interception and tampering, especially in high-risk or hostile countries.
  

Destruction
One of the conditions for proper use of an OTT system, is that the keytapes are destroyed im­me­di­a­tely after use. This is done to prevent re­construction of the plain­text by a malicious party from (partly) recovered keytapes.

To ensure that the keytape could not be used again, some OTT cipher machines had a built-in knife that cut the keytape in half upon leaving the tape reader. For proper security however, the tapes had to be destroyed completely, e.g. with a special device, such as the KD-100 shown in the image on the right. It produces paper powder.

 More information

  




Developments
Germany
During WWII, the German Army relied on hand ciphers and rotor-based cipher machines, such as the Enigma, the Siemens T-52 Geheimschreiber and the Lorenz SZ-40/42. In 1943, Siemens developed their first online mixer machine based on the above principle. It was named T-43 and less than 50 of them were built. The machine was based on a patent that had been filed by Siemens back in 1921 At the end of WWII, the Germans destroyed most of these T-43 machines. The ones that survived were captured by the Americans and later also by the British.

Netherlands
From 1946, the Dutch state-owned PTT 1 developed its own range of mixers, based on the principle described above. As PTT didn't have sufficient production capacity, the machines were manufactured by Philips Usfa in Eindhoven (Netherlands). The first machine to be released in 1946 was the relay-based Colex, followed by the valve-based Ecolex I in 1950. In 1955, the Ecolex I was succeeded by the transistorised Ecolex II, which was also adopted by NATO. After that, Philips Usfa took over the development of cipher machines, resulting in 1963 in the Ecolex IV that featured full synchronisation. According to a former company director, Philips payed royalties to Professor Dr. Ir. Oberman, the initial developer at the Dutch PTT Research Labs, for the use of his patents [10]. The Ecolex IV was the last mixer developed in the Netherlands.

Norway
In 1952, a similar patent was filed 2 by Bjørn Røhrholdt – a Colonel, engineer, veteran and liason of the Norwegian Army – and Kåre Meisingset of STK in Norway [2]. The collaboration of the two engineers resulted in the development of the ETCRRM, a mixer machine that used valves (tubes) rather than electric relays. The machine was soon adopted by the Americans for communication at the highest level and later also by the newly established NATO. At height of the Cold War, the ETCRRM was used at the heart of the Hot line between Washington and Moscow.

  1. PTT = Staatsbedrijf der Posterijen Telegrafie en Telefonie. (state company for post, telegraphy and telephony). Privatized in 1989 and currently known as KPN.
  2. So far, we've been unable to find this patent.
TEMPEST problems
Even when the regular conditions for use of a one-time pad (OTP) are met, there is still a risk of losing intelligence when the equipment emanates compromising signals. In modern terminology this is known as side channel leakage. Within NATO the phenomenon is known as TEMPEST. There are various types of compromising emanations, such as acoustic, optical, electrical and via RF energy (radio). The effect was first discovered at Bell Labs during WWII in 1943. It was discovered that teleprinters could cause glitches (spikes) that could be picked up at a considerable distance.

The first problems with OTT cipher machines (mixers) were discovered in the late 1950s and early 1960s. It prompted the manufacturers to add shielding and filtering to the design. In some cases, multiple measures had to be taken to avoid potentional leakage of intelligence-bearing signals.

 More about TEMPEST


Demise
The main problem with OTT machines, is the key distribution. Outstations had to have a large stock of fresh keytapes, which often led to serious supply problems, especially on busy cir­cuits. Although for diplomatic and high-grade military traffic, secrecy is of the utmost importance, the distribution issue became a major burden. It was the main reason for prompting the development of a new generation of cipher machines that didn't need the bulky and costly one-time tapes.

The solution came in the late 1950s and early 1960s, in the form of electronic cipher machines that were based on shift-registers. The first machines, like KW-26 and BID-610, were made with valves, but the invention of the transistor soon made the machines smaller and more energy-efficient; for example the KW-7. Although the key generators of these so-called TROL machines did not produce a truly random key stream, the use of non-linear feedback shift-registers (NLFSR) enabled the generation of high-quality pseudo-random key streams with a long cipher period, that could not easily be broken by an adversary, even when the algorithm was known. 1

Consequently, most military OTT-machines were replaced from the mid-1960s onward, by shift-re­gis­ter-based alternatives. For diplomatic traffic, governments relied on the security of OTT machines for several more decades, until newer and more advanced solutions became available.

 More about TROL cipher machines

  1. In the early days, this was not always the case, especially when linear feedback shift-registers were used (LFSR). The first generation of TROL machines from several countries, could be broken when the algorithm was known. This changed when the developers started using increasingly complex non-linear solutions.


Related patents
  1. US Patent 1,310,719 — Secret Signalling System
    Gilbert S. Vernam on behalf of Bell Telephone Laboratories, 13 September 1918.


    This patent, filed by Gilbert S. Vernam on 13 September 1918, describes the basic exclusive-OR (XOR) operation that forms the basis of all modern cipher machines and algorithms, although he did not use the term XOR at the time. In Boolean Algebra, XOR is also known as modulo-2 addition. Note that Vernam described the use of his invention for 5-bit teleprinter traffic. The drawing above shows two distributors that are used for the serialising and de-serialysing the 5-bit data words (the circular objects). In the patent, Vernam does not claim the use of one-time tape to make the cipher unbreakable.

  2. German Patent 371,087 — Verfahren, Vorrichtung und
    Schaltungsanordnung zur Nachrichtenübermittlung in Geheimschrift

    Karl Ammon on behalf of Siemens & Halske, Berlin, filed 10 July 1921.


    This patent, filed in 1921 by Karl Ammon on behalf of Siemens & Halske in Berlin (Ger­ma­ny), presents a system that is very similar to the orignal patent of Vernam (1918). It des­cribes a system in which two perforated tapes are read simultaneously.
Known mixers
Below is a non-exhaustive list of known one-time tape cipher machines. Unusual specifications are highlighted. If you come across an OTT machine that is not listed here, please let us know.

YearModelBitsAlphabetManufactuerCountry
1926 Telekrypton 5 ITA-2 Western Union UK/Canada
1938 M-100 5 MTK-2 ? USSR
1943 Rockex 6 ITA-2 HMGCC UK
1943 5-UCO 5 ITA-2 HMGCC UK
1943 T-43 5 ITA-2 Siemens Germany
1946 Colex 5 ITA-2 PTT Netherlands
1946 C-446/RT 5 ITA-2 Hagelin Sweden
1950 Ecolex I 5 ITA-2 Philips Netherlands
1950CH-3-A5ITA-2OlivettiItaly
1952 CX-52/RT 5 ITA-2 Crypto AG (Hagelin) Switzerland
1952 TC-52 5 ITA-2 Crypto AG (Hagelin) Sweden
1953 ETCRRM 5 ITA-2 STK Norway
1954 Ecolex II 5 ITA-2 Philips Netherlands
1955TC-555ITA-2Crypto AG (Hagelin)Sweden
1956 Mi544 5 ITA-2 Lorenz Germany
1956 T-37i CA 5 ITA-2 Siemens Germany
1956UG-20225ITA-2?Israel
1957 Schlüsselgerät D 5 ITA-2 Siemens Germany
1959 Ecolex III 5 ITA-2 Philips Netherlands
1959RTE-595ITA-2Crypto AG (Hagelin)Switzerland
1959 Derby BID/570 5 ITA-2 STK Norway
1960 Selma 5 ITA-2 STK Norway
1962 Noreen 6 ITA-2 HMGCC UK
1962 M-190 5 ITA-2 Siemens Germany
1963 Ecolex IV 5 ITA-2 Philips Netherlands
1963 TCE-160 5 ITA-2 STK Norway
1966 ULES-64 5 ITA-2 Crypto AG (Hagelin) Switzerland
1967 T-352 Dudek 5 ITA-2 Teletra Poland
1968 M-105 11 Proprietary ? USSR
1970TP-8455ITA-2ACECBelgium
1972 TT-360 5 ITA-2 Mils Austria
1975 ME-620 5 ITA-2 Mils Austria
1982 ME-840 5 ITA-2 Mils Austria
1986 ME-640 5 ITA-2 Mils Austria
 
Known keytape generators
YearModelBitsTypeManufactuerCountry
1953Hazardo5?Atheneum StiftungLiechtenstein 1
1953Würfel5RNGReichertGermany
1955H-5025PRNGHellGermany
1955Erolet5?PTT, PhilipsNetherlands
1957ZG-575?Crypto AG (Hagelin)Switzerland
1959KTP-35?STK (Thales)Norway
1960STG-50015RNGReichertGermany
1961STG-50025RNGReichertGermany
1962STG-50035RNGReichertGermany
196352245RNGReichertGermany
1967A-67235RNGMilsAustria
1992ME-6005RNGMilsAustria
  1. The Atheneum Stiftung had its statutory seat in tax-paradise Liechtenstein, although its directors and employees were all based in Germany. Most of them also worked for the German cipher authority ZfCh.
Specifications
References
  1. Wikipedia, One-time pad
    Accessed January 2013.

  2. Norwegian National Security Authority (NSM), Årsmelding 2008
    NSM Annual Report 2008 (Norwegian). Noen kryptosuksesser. p. 15.

  3. US Patent 1,310,719, Secret Signalling System
    Filed 13 September 1918.

  4. German Patent DE371087
    Patent describing the principle of a mixer machines. Filed: 10 July 1921.

  5. Melville Klein, Securing Record Communications. The TSEC/KW-26
    NSA, CCH, 2003. Updated 19 March 2004.

  6. Telegraphic Code to Insure Privacy and Secrecy in the Transmission of Telegrams
    Frank Miller, 1982. Via WikiSource.

  7. Steven M. Bellovin, Frank Miller: Inventor of the One-Time Pad
    CUCS-009-11. Columbia University, Department of Computer Science.
    Cryptologia 35(3), 12 July 2011. p. 203-222.

  8. David Kahn, The Codebreakers
    Macmillian, New York (USA). First printing, 1967.

  9. John Bowen (G8DET), Remembering the BID/30 (5-UCO)
    Personal correspondence, 7 July 2019.

  10. Anonymous former company director of Philips Usfa
    Interview at Crypto Museum. April 2013.
Further information
Any links shown in red are currently unavailable. If you like the information on this website, why not make a donation?
© Crypto Museum. Created: Saturday 08 September 2012. Last changed: Thursday, 27 August 2026 - 08:45 CET.
Click for homepage