|
|
|
|
|
|
|
T&N ← SG-39 ← Enigma
There were at least two versions of the machine,
the first of which had a keyboard and printer.
It was demonstrated in early 1955 to members of the US
Army Security Agency Europe (ASAE) [4].
The internal keyboard and printer were later replaced by an interface that allows
any regular Baudot teleprinter to be
used instead. This version is shown in the image on the right.
At its right are connections for teleprinter and line.
Neither version seems
to have survived, except for the cipher unit of the later version, which is shown
in the image below. It has two sets of rotors: 7 Hagelin-type pin-wheels
at the top — the stepping wheels — and 8 cipher rotors below.
In between the rotors are 10 intermediate stators.
|
|
|
This means that all 26 cores must be installed.
Irregular rotor stepping is achieved by advancing
the eight cipher rotors
under control of seven Hagelin-type pin-wheels. 4
In order to obtain a maximum length cipher period,
each pin-wheel has a different number of positions (29, 31, 37, 41, 43, 47, 53),
all of which are primes.
As far as we know, very few units were made, probably 10 to 20 [1].
Although it was initially thought that the device was never used in service,
an NSA document reveals its
use by the German Foreign Office (Auswärtiges Amt) [6].
|
|
|
|
It is likely that — like the Hagelin HX-63 super rotor machine —
the High Speed Enigma came a bit too late, and was superseded in the mid-1960s
by solid state (electronic) TROL devices such as ELCROTEL
and KW-7.
When the machines were decommissioned, their rotor cages
were removed, whilst the devices themselves were scrapped. As far as we know, there
are no complete surviving machines. The cipher unit shown above, is believed
to be one of only four surviving units.
|
 |
-
As the official designator for the High-Speed Enigma is currently unknown,
we will use the abbreviation HSE for now. The machine is also known as
T&N High Speed Enigma and as T&N Enigma.
-
T&N later became Telenorma (TN) and then Tenovis.
In November 2004 it was acquired by Avaya Inc [2].
-
At the time (1957) the organisation was still known as
Studiengesellschaft zur Förderung Wissenschaftlicher Arbeit mbh. (SFWA) -
translated: Society of Scientific Work (SSW). In 1959 this became the
Zentralstelle für das Chiffrierwesen (ZfCh)
— the German cipher authority. Today it is known as the BSI.
Although it is incorrect, we have used the name ZfCh
throughout this article, as most people are not familiar with its former name.
-
Named after Boris Hagelin who first
used them in his B-21 cipher machine.
|
The image below shows the features and connections of the HSE Mark II
— the online version that was inserted between a teleprinter and
the telex line. As far as we know this is the only surviving photograph
of this model. The device is housed in a metal enclosure with grey
hammer paint finish. The lower half has a recessed front panel that
holds the controls and indicators, including a meter that shows
the line current. To the right of the meter is the T&N logo.
At the bottom is the on/off switch (Ein/Aus).
Directly above it are the switches for Plaintext (Klar) and
Ciphertext (Geheim). At the right is a recessed panel with the
connections for the teleprinter and the telex line.
The upper part of the device contains the cipher unit, which is
slightly tilted for easier operation. It is protected by a
removable case lid. Removing the lid reveals the cipher unit as shown
below. The cipher unit can be extracted from the device by releasing
two locking levers – one at either side of the unit – after which it can
be lifted from a set of four connectors at the rear.
|
 |
|
Differences with wartime Enigma
|
 |
 |
- More cipher rotors (8)
- Intermediate stators (10)
- Removable wiring cores (26)
- Wiring cores with 32 contact points
- Irregular rotor stepping (controlled by 7 pin-wheels)
- Motor-driven
- Faster operation (7 characters per second)
- Automatic encryption/decryption
- Compatible with ITA-2 teleprinter
- Online and offline use
- No reflector (UKW)
- Non-reciprocal (a letter can become itself)
- No plugboard (Steckerbrett)
- No ring setting (Ringstellung)
|
|
Although very little is known about the development of the HSE, it is certain
that at least two versions were developed. To discriminate between the two models,
we have given them the provisional names Mark I and Mark II in the text below.
These are not the original designators.
|
This is the initial version of the device as it was demonstrated by
Mr. Weintraub of T&N on 21 January 1955 to a delegation of the US
Army Security Agency Europe (ASAE). From photographs that were included with the
intelligence report about this visit,
it is clear that this version had an integrated keyboard and two printers [5].
It is likely that this version was for offline traffic only. When entering
plaintext on the keyboard, it was encrypted by the device and the output was
printed on one of the strip printers above the keyboard. The resulting ciphertext
had to be retyped on a regular teleprinter for transmission.
When receiving a ciphertext, the device had to be switched to ENT (Entschlüsseln,
decipher) after which the text had to be entered manually on the keyboard.
The resulting plaintext was then printed on the other strip printer.
|
|
|
This is a further development, in which the integrated
keyboard and printers were replaced by a telex interface, allowing the device to be
used with any type of teleprinter that uses the
ITA-2 (Baudot) standard. This version was suitable for
both offline and online traffic.
At the right side are connections for teleprinter and line.
At the front panel is a cipher/decipher switch, a line current meter
and additional controls and indicators.
It also shows the T&N logo.
In addition, the
cipher unit was slightly updated and received two separate rotor covers: one for
the pin-wheels, and one for the cipher rotors and the
intermediate stators (the actual scrambler). The cipher unit shown at the top of
this page is from this version.
|
|
|
 |
|
Differences between Mark I and Mark II
|
 |
 |
|
Compared to the Mark I, the Mark II version has the following differences:
|
- No keyboard and printers
- Interface for telex subscriber line (or radio)
- Line current meter
- Interface for connection of a teleprinter
- Two separate rotor covers (each with a physical lock)
- Cipher rotor positions marked 01-32 (rather than A-Z, 1-6)
- Suitable for online traffic
|
Below is the simplified setup of the HSE Mark I, of which only the transmission
path is shown here. The encryption is performed by the cipher unit, in combination
with additional electronic circuits that are not shown here. Keyboard and printer(s)
are integrated with the device. There is no connection for a telex line.
Consequently the device was suitable for offline traffic only.
Below is the simplified setup of the online HSE Mark II. Again, only the
transmission path is shown here for simplicity.
In this version, keyboard and printer(s) have been replaced
by interfaces for connection of a standard ITA-2 compatible
teleprinter and a regular telex subscriber line.
Alternatively, the output can be used to drive a (tele)printer or a tape puncher.
|
Of these machines, the Enigma is arguably the most
well-known one, not least because more than 35,000 units were used
during the war by the German Armed Forces.
The machine was adopted by the Reichswehr in 1927 and entered
service in 1930 as Enigma I (Pronounced: one).
In 1934, the German Navy (Kriegsmarine) followed suit with the
introduction of the Enigma M1, which was compatible
with the Army's Enigma I.
The M1 eventually evolved into the M2 and M3.
All of these machines had three cipher rotors, a reflector (UKW)
and a plugboard (Steckerbrett).
|
|
|
In addition, the Kriegsmarine ordered a modified machine with an extra
cipher rotor, which was introduced in 1942 as the Enigma M4.
It was intended for use on special circuits, such as for communication
with the much-feared U-boats, and is backward compatible with the
Enigma I.
|
| |
Simplified Enigma M4 circuit diagram
|
The diagram above shows a simplified circuit diagram of the
Enigma M4. At the right are the keyboard (input)
and the lamps (output). The device is battery powered and has
four cipher rotors, of which only the three rightmost ones (1-3) are
driven. The fourth rotor, in German known as the Zusatzwalze
(extra wheel), is not driven and is actually a stator.
At the left is a reflector (UKW). It makes the machine reciprocal
(i.e. reversible) but also introduces a cryptographic weakness.
When the stator (ZW) is set in the 'A'-position, the machine is
backward compatible with Enigma I.
Each time a key is pressed, the rightmost rotor (1) makes a single
step. After one full revolution of this rotor, the middle rotor (2)
also makes a single step. Likewise, the leftmost rotor (3) makes a
single step after a full revolution of the middle rotor, which means
that it will barely step at all. This behaviour is similar to the
motion of an odometer and is known as Enigma stepping.
➤ More about Enigma M4
|
The first version was intended for telegraphy and had 32 contact points on the
rotors. After several design iterations however, it was decided to make the machine
backward compatible with Naval Enigma M4 and therefore also with the
Army's Enigma I.
The SG-39 had several improvements over the Enigma M4.
It was motor-driven, which made the keyboard easier and lighter
to operate.
Instead of the lamp panel it had a strip printer that printed the encrypted
ciphertext (CT) directly to paper. A second printer was connected to the
keyboard and printed the plaintext to another paper strip (PT). In addition,
the reflector (UKW) was configurable, just like Enigma's
UKW-D.
The biggest improvement however, was the addition of three
Hagelin-type pin wheels (N1-N3) that controlled the
stepping of the three cipher rotors.
|
| |
Simplified SG-39 circuit diagram
|
Each pin-wheel had a different number of positions (21, 23, 25)
and made a single step on each key-press. Furthermore, each position of each
pin-wheel had a pin that could be set to active or inactive. When an active
pin engaged a sensing mechanism, it caused one or more cipher rotors to step.
As a result, all cipher rotors moved more frequently and irregularly.
In addition, the cipher rotors had one or two stepping notches to allow
the old odometer-style Enigma stepping.
Despite the many improvements over Enigma, and the fact
that it remained backward compatible with the Enigma, the
SG-39 never evolved past the prototype stage.
Eventually, the SG-41 (Hitlermuhle) – another invention
of Fritz Menzer –
was selected as a possible replacement candidate for Enigma,
although that machine met with fierce critisism, mainly because of its high weight.
➤ More about Schlüsselgerät 39
|
The development of the SG-39 machines was abandoned some time in 1943.
When an American TICOM inspection team led by major Howard C. Barlow visited
the T&N factory in Frankfurt-am-Main shortly after the war, in June 1945,
three prototypes were identified.
Unfortunately, only one was complete and had
just been sent to a different location. Eventually, Barlow returned home with
the most incomplete prototype of which the rotors and printers were missing.
It is this prototype that is shown in the image on the right.
It was taken from the NSA publication
German Cipher Machines of World War II
by David P. Mowry [7 p.20].
|
|
|
After WWII, cipher security in Germany
became the responsibility of a new
organisation under supervision of
Dr. Erich Hüttenhein.
During WWII, Hüttenhein had been the
chief of the cryptanalytical research unit of the Third Reich
(OKW/Chi).
After the war, the Americans kept him onboard, and in 1947 made him the head of the
Studiengesellschaft zur Förderung Wissenschaftlicher Arbeit mbh.
(SFWA) — translated: Society for Scientific Work (SSW) — which fell under the
responsibility of the post-war intelligence service
Organisation Gehlen (OG).
In 1956, control of the intelligence services was handed over by the Americans
to the German Government, after which the OG was succeeded by the
Bundesnachrichtendienst (BND).
In 1959, the SFWA became the
Zentralstelle für das Chiffrierwesen (ZfCh)
— the centralized German cipher authority —
of which Hüttenhain
remained the director until his retirement in 1970.
Although the development of cipher machines in Germany had been abandoned at the end of the
war, the new German Government had a need for secure communication for its diplomatic
and military traffic. Several German companies with experience in the
field of cryptography, were asked to develop new cipher machines.
Around the beginning of 1954, three major cipher machines were under
development in post-war Germany [4][5]:
|
|
The H-54 was an improved version of the
Hagelin CX-52, built by Hell
in Kiel (Germany) under licence of the Swiss company Crypto AG.
The fully mechanical device was intended for tactical traffic of the German Army
— the Bundeswehr. The Lorenz Mixer Mi544 was a
One-Time Tape cipher machine, developed at
C. Lorenz AG in Stuttgart by Dr. Grimsen [4].
When used correctly, this machine was absolutely secure.
It was intended for traffic at all classification levels.
|
The High Speed Enigma (HSE) was developed at
Telefonbau & Normalzeit (T&N)
and was a further development of Schlüsselgerät 39 (SG-39),
which had been developed before and during WWII,
but was never taken into production.
Development of the HSE was started in the summer of 1953 and by December 1954
the first prototype was ready for review [5].
It was much more advanced than the SG-39 had ever been. It had 8 electric
cipher rotors, plus 7 Hagelin-type pin-wheels.
|
| |
Rotors (R), stators (S), cores (C) and pin-wheels (N) of the High Speed Enigma
|
The device came with 26 wiring cores (C1-C26), that
were all placed in the lower half of the cipher unit. Each of the 8 cipher rotors
(R1-R8) contained two wiring cores (16 in total). The remaining 10 cores were
used as stators (S1-S10) that were placed in between the rotors.
The 7 pin-wheels (N1-N7) controlled the movement of the cipher
rotors (R2-R8).
➤ More
The basic idea that the cryptographic strength of the machine could be
enhanced significantly by adding more rotors, was already known by the
original inventor of the Enigma, Arthur Scherbius, as early
as 1918. When he worked on the development of his
2-rotor prototype (Probemaschine),
he also made an experimental version with 7 rotors. Although this greatly
improved the cipher strength, it faced many contact problems that were
caused by mechanical design constraints.
The idea of placing rewirable intermediate discs (stators) in between
the rotors, dates back to
patent DE 554,421
that was filed by ChiMaAG in 1928 [9], but never made it into an actual design.
In late 1954, NSA top cryptologist Frank Raven eagerly awaited
the first prototype of the HSE, probably for review and cryptanalysis.
Colleagues from the ASAE were supposed to visit T&N and file a
report about the new machine, but by January 1955 he still hadn't heard from them.
In correspondence with NSA's William Friedman
he even suggested ordering one from T&N for the price of DM 12,000, but
Friedman later informed him that the machine could not be ordered [10].
|
On 2 February 1955, a delegation of the European section of the
US Army Security Service (ASAE) visited T&N to see wether it was
possible to establish 'favorable relations' with the company [5].
In this context, it meant that T&N would only sell the new machine to
friendly nations and not to potential enemies like the Soviet Union (USSR),
its satellites and other Warsaw Pact countries.
On the occasion, Mr. Weintraub of T&N demonstrated a prototype
of the High Speed Enigma (HSE) that had just become available in December 1954.
Weintraub, who reportedly displayed a cooperative attitude, told the delegation members
that if they wanted to know more about the current cryptologic developments
in West Germany, they should contact
Dr. Erich Hüttenhain [5].
The initial machine, which was demonstrated in 1955, had a number of
drawbacks. For transmission, the ciphertext had to be re-typed on a regular
teleprinter. Likewise, any ciphertext received from a teleprinter line, had
to be re-typed on the HSE, which was time consuming and gave rise to
entry mistakes. The design team therefore went back to the drawing board
and redesigned the entire machine, except for the cipher unit.
The keyboard and the two printers were removed. Instead the machine was
fitted with a teleprinter interface, that allowed the machine to be inserted
between any regular teleprinter and the telex line.
It is believed that a small quantity of the redesigned machine was built
in 1957, which were then used by the German Foreign Office [6].
➤ Read the full report
|
 |
|
Foreign Office
Auswärtiges Amt
|
 |
 |
|
Apart from the report of the demonstration in February 1955,
which comes from in internal ASA/NSA memorandum [5],
it is difficult to find any evidence of the existence
and usage of the High Speed Enigma, but there are some hints in later
publications. For example, in the 2002 book Gegen Freund und Feind
by Peter F. Müller and Michael Mueller [3], we read on page 363:
|
In Kooperation mit dem Unternehmen "Telefonbau und Normalzeit" entwickelte
Pullach dann eine neue Chiffriermaschine, die an die Technik der ENIGMA des
Zweiten Weltkriegs anknüpfte.
|
In this context, Pullach refers to a city, south of München (Germany),
where the German intelligence service OG (later: BND) was located.
The source for the above quote was a 1960 top secret internal BND memorandum, 1
which literally states [8]:
|
In Zusammenarbeit mit der Firma "Telefonbau und Normalzeit" enstand
eine Chiffriermaschine, welche die bekannte "Enigma" des zweiten
Weltkrieges ersetzt und verbessert.
Translated: Together with T&N, a ciphermachine was developed which replaced
and improved the well-known Enigma from WWII.
It confirms that the new machine was a much improved version of the
Enigma. It is likely that the quote actually refers to the
SG-39, which had been developed at T&N during the war,
and was in fact already an improved Enigma. The memo also confirms that
the HSE was developed in cooperation with the
Zentralstelle (ZfCh) rather than
OG/BND [8]. 1
Another interesting hint can be found in the classified NSA story
Der Fall WICHER
(the Wicher case) by Joseph A. Meyer [6].
It was compiled from TICOM interviews with high-ranking
German cryptologists, complemented by Meyer's own remarks.
On page 12 of this story, which was declassified by NSA in 2007,
we find the following remark:
|
After the war, when the reconstituted West German Government established
its cryptography, the ENIGMA was not brought back into service.
Instead, the Foreign Office adopted the T&N (Telefonbau und Normalzeit) machine
— a development from Menzer's original SG-39, but much more secure.
|
This source confirms that the machine that was developed by T&N,
was indeed based on SG-39 and Enigma, and that it
was much more secure. It also confirms that the machine was actually used
by the German Foreign Office (Auswärtiges Amt),
which means that there must have been more
machines than just a few prototypes.
This seems to be confirmed by the surviving cipher unit in the Crypto Museum
collection, which bears the serial number 007.
|
-
Many thanks to Peter F. Müller and Erich Schmidt-Eenboom for sharing the
source material for their 2002 book Gegen Freund und Feind [3].
They have also kindly given permission to reproduce this material here [8].
|
Around 1959, the first problems with respect to compromising emanations
surfaced. This was a worldwide problem – within NATO known as TEMPEST –
that affected nearly all teleprinter cipher machines.
It is caused by the transmission
relay of the teleprinter, which causes transient pulses of a
wideband nature. As a result, narrow pulses from the plaintext may appear
in the transmitted ciphertext, which allows an eavesdropper to reconstruct
the plaintext from an intercepted line.
Similar problems were found with other teleprinter cipher machines,
such as the Philips Ecolex II where it was discovered
in 1965 [11]. Most manufacturers solved the problem by
inserting filters in the transmission line.
In the case of the HSE, T&N developed a filter set for which they
registered a patent in 1959 [IX]. Aparently, the filter was not
able to filter out the compromising pulses completely, so a second solution
was devised in which the pulses were masked by injecting extra transient
noise, generated by the machine's own motor, directly in the transmission path.
This solution is described in German Patent DE 1,110,209
[XI], which was also filed by T&N in 1959.
|
Aound 1960, the first fully electronic cipher machines were developed in
several countries, including Germany. This development was linked to a
NATO competition under the name TROL, which stood for
Tapeless Rotorless On-Line. TROL machines marked the transition from
(electro)mechanical cipher machines to fully electronic ones, in which the
cipher rotors (and pin-wheels) were replaced by electronic shift registers.
The first TROL systems were rolled out in NATO countries between
1966 and 1968.
They were faster and much more reliable than rotor machines.
Germany's contribution to the NATO contest was a machine known as
ELCROTEL, developed by Siemens in München.
Although it had the highest score in the NATO evaluation, it was not chosen as
NATO's TROL machine, probably for political reasons. Instead the bidding was
lost to the British ALVIS (BID/610) and later to the
American KW-7.
Nevertheless, ELCROTEL was chosen by the Germany Ministry of
Defense and by the Dutch Air Force, where it remained in service for many years.
It is therefore likely that the German Foreign Office made a similar decision
and replaced its High Speed Enigma (HSE) by a more modern machine, like
ELCROTEL, in the mid-1960s.
➤ More about TROL machines
|
At the heart of the HSE is a driven scrambler that pseudo-randomly
transposes the alphabet a number of times in an irregular and frequently
changing manner.
This cipher unit consists of rotors, stators, wiring cores and pin-wheels,
each of which are further described below.
|
Each High Speed Enigma (HSE) was supplied with 26 wiring cores, identified with
the 26 letters of the Latin alphabet (A-Z). Each wiring core has 32 contacts at
either side; one for each of the 32 characters of the
5-bit ITA-2 telegraphy alphabet
(25). The contacts at the left side of the core are connected to the contacts
at the right side of the core in a scrambled manner.
Each core is wired differently.
The 32 contacts are marked at the circumference of the core in this order:
123456ABCDEFGHIJKLMNOPQRSTUVWXYZ
All cores of the two known surviving core sets are marked on the right hand
side with the number 001 . This probably identifies the wiring series. It is
likely that the developers had planned to release multiple series, for example
for different users. At present however, only series 001 is known.
When setting up the machine with the daily key, all 26 cores
must be installed in the lower half of the cipher unit (C1-C26), divided over the
rotors (R) and stators (S), as follows:
The use of removable wiring cores is very similar to the
use of wiring cores in the 1972 rotors of the
Russian M-125-3 (Fialka) cipher machine.
Unlike Fialka however, a HSE core is constructed in such a
way that it cannot be flipped (i.e. front to back). This reduces the number
of possible settings by a factor of 2 for each core, or 226 = 67,108,864
times for the entire machine.
➤ Core wiring
|
|
The lower half of the cipher unit holds eight cipher rotors of which the
stepping is controlled by the seven pin-wheels in the upper half.
Each rotor is made of grey plastic and is fixed in place, although its wiring
is held in a removable yellow plastic insert that accomodates two cores.
|
In the diagram above, the rotors are shown in blue. As each rotor takes
two wiring cores (e.g. C3 and C4), this means that 16 of the available
26 cores are installed in the rotors, subject to the
and the inner key settings.
The remaining ten cores are used for the stators (see below).
In order to remove the yellow insert from a cipher rotor, the rotor
must first be set to its neutral position,
which means that the red line should be facing the front of the cipher unit.
In that case, rotor position 08 should be visible
through the window in the front rotor cover.
|
|
|
The cores and the yellow insert are constructed in such a way that the
cores cannot be installed the wrong way around (i.e. flipped). This means
that the series number (001) must always face the right side of the rotor.
It is possible however to install each core in 32 different positions,
indicated by the letters and numbers on the circumference of the wiring
cores (1-6, A-Z).
When installing the cores in the yellow insert, the current positions of
the cores are
visible through two small windows in the side of the insert.
The positions are specified as part of the inner key.
|
|
|
|
In the image above, core C is
installed in the left half
of the insert, whilst core U is
installed in the right half,
with their core positions defined by two characters,
for example T5 as shown here.
Note that the position window has an offset of -10 from the
contact at the dead top of the core.
If '1' is at the the dead top of the core, the character
visible in the position window is 'Q'.
Once the cores have been correctly installed in the yellow insert,
the insert can be placed back in the rotor.
Note that the two cores always move in tandem (i.e. they step at the
same time).
Also note that each rotor has a black ring that shows the current position
(01-32). The start position of each rotor is set as part of
the outer key, and must be different for each message.
|
|
Of the 26 available wiring cores (C1-C26), 16 are used for the rotors
(2 per rotor). The remaining 10 cores are used as stators
(S1-S10). They are inserted between the rotors and are shown in purple
in the diagram above.
A stator adds an extra alphabet transposition in
a static manner.
|
A stator consists of a plastic yellow frame into which a core can be
installed. Both the frame and the core are constructed in such a way
that the core must be inserted into the frame
from the right.
Furthermore, the core cannot be flipped, which means that its
series-number (001) has to face the right side of the frame.
The front of the yellow frame has a red tip that must point to the
bottom when inserting the stator (i.e. the yellow frame with the
core) into the desired stator bay, subject to the keying
instructions and the inner key settings.
|
|
|
Like the rotors, a stator frame has a small
window through which the
current position of the core is visible.
Note that the position window has an offset of -6 from the contact
at the dead top of the core. If '1' is the dead top of the core,
the character visible in the position windows is 'U'.
Seven stators are installed in between the eight rotors,
plus two between the left end plate and the first rotor (R1),
and one between the rightmost rotor (R8) and the right end plate.
Unlike a rotor, a stator does not move during
encipherment. Nevertheless, it contributes significantly to the
strength of the cipher. It is comparable to the non-driven extra
rotor (Zusatzwalze) of the Naval Enigma M4,
but rather than just one static alphabet substitution, the HSE has ten of them.
|
|
At either end of the rotor stack is a 32-contact
end plate that serves as input and output, comparable to the Eintrittswalze
(ETW) of the Enigma cipher machine.
It should be noted however, that, unlike wartime Enigma, the HSE
does not have a reflector (UKW) and, hence, does not suffer from the weakness
that a letter can't be enciphered to itself. Consequently, the function of the
input and output plates must be swapped when switching from encryption (VE)
to decryption (ENT).
|
The image on the right shows the
leftmost end plate (EL), which is integrated
with the bay for the first two stators (S1, S2). Its construction is very
similar to that of Enigma's entry disc (ETW), but
it is made of nylon rather than bakelite.
When the machine is in cipher mode, the leftmost end plate is also known as
the input disc. It has 32 silver-plated contacts that are arranged in a
circle, in such a way that they connect to the 32 contacts at the left side of
the first stator (S1). The left end plate is wired to
two large connectors (PL1, PL2) at the rear of the cipher unit.
|
|
|
|
In the Enigma, rotor stepping is controlled
by one or more notches of the adjacent rotor. The rightmost rotor steps
on each key press. When its notch is engaged, the rotor to its left also
makes a single step. Likewise, the leftmost rotor is controlled by the middle one.
As a result, the middle rotor only steps once every 26 characters, and
the leftmost rotor barely moves at all.
|
This odometer-style stepping makes Enigma regular and
predictable, which can be regarded as an exploitable weakness of the cipher system.
In the HSE, this problem was solved by introducing Hagelin-type pin-wheels
to control the motion of the cipher rotors. On each key-press,
all pin-wheels make a single step. Furthermore, each pin-wheel has
a different number of positions (29, 31, 37, 41, 43, 47, 53), all of which
are prime numbers to ensure a maximum length cipher period.
The image on the right shows the leftmost pin-wheel, with several
inactive pins.
|
|
|
|
The pin-wheel positions are numbered 01, 02, 03, etc.
Furthermore, each position has a pin that can be set to the right (active)
or left (inactive). When an active pin engages the sensing
mechanism, it causes the corresponding cipher rotor to step.
According to Patent DE 977,691 of 1954,
the leftmost rotor (R1) steps on each input character.
The second rotor (R2) is controlled by the first
pin-wheel (N1), etc. The last rotor (R8) is controlled by the last
pin-wheel (N7).
Consequently, all rotors move frequently and
irregularly, which greatly improves the strength of the cipher.
|
| Pin-wheel | Length | Sensing 1 | Offset 2 | Controls | Remark |
|
|
| - | - | - | - | R1 | R1 steps on each character |
| N1 | 29 | 20 | -10 | R2 | |
| N2 | 31 | 21 | -11 | R3 | |
| N3 | 37 | 25 | -13 | R4 | |
| N4 | 41 | 28 | -15 | R5 | |
| N5 | 43 | 29 | -15 | R6 | |
| N6 | 47 | 32 | -16 | R7 | |
| N7 | 53 | 36 | -18 | R8 | |
|
-
The sensing position is specified when position 01 is visible in the
window at the front of the machine.
-
The offset is the distance between the sensing position and the number
visible in the window at the front.
|
Below is a simplified circuit diagram of the cipher unit of the HSE.
At the top left is a motor that is running constantly.
It drives a clutch that is controlled by the input circuit.
As soon as a character is available at the input
(e.g. when a key is pressed), the clutch is engaged (start), after which the main
axle makes one full revolution. This causes the first rotor (R1) to make a
single step. It also causes all seven pin-wheels (N1-N7) to make a single step.
Depending on the positions of the active pins on the pin-wheels, this
causes the remaining rotors (R2-R8) to step conditionally.
Once the rotors have stepped to their new positions, a character can be
enciphered. For this, the character first has to be converted from the
5-bit domain to one of 32 discrete electric lines. This line then
enters the rotor stack via one of the 32 contacts of the left
end plate (EL). It then passes all stators and rotors from left to right,
until it leaves the stack via one of the 32 contacts of the right
end plate (ER). The output line is then converted back to 5 bits,
so that it can be printed.
|
| |
Block diagram of the HSE Mark I
|
The block diagram above shows how this was done with the HSE Mark I.
It shows the machine in cipher mode. The keyboard directly delivers
the signals from the 32 keys to the left end plate. It also (mechanically)
delivers the same key in 5-bit format, which is passed directly to the
plaintext printer (PT). The output from the right end plate is converted
to 5-bit format by means of a diode matrix, which is then passed to the
ciphertext printer (CT). This version is for off-line use only.
|
| |
Block diagram of the HSE Mark II
|
The block diagram above shows the HSE Mark II in cipher mode.
At the heart is the same rotor stack, but the keyboard and the two
printers have been removed. Instead, it takes the serial data signal
from a teleprinter (at the left), converts it to parallel 5-bit
data, which is then decoded into 32 individual lines that are
connected to the left end plate. The output from the right end plate
is encoded to parallel 5-bit data, which is then converted to a
serial signal that can be passed directly to the telex line.
Alternatively, this line can also drive a printer or a tape puncher.
In decipher mode, the above process is reversed. In that
case the right end plate (ER) acts as the input and the left end plate (EL)
delivers the output. It is currently unknown how this switching from
cipher to deciper mode was implemented. It is likely though that
this was done by means of electromagnetic relays.
|
The diagram below shows the electric parts that are present inside the
cipher unit. At the top right is the motor (M) which is
not part of the cipher unit. It is housed inside the machine's main
body, and is coupled to the cipher unit by means of a cogwheel.
The motor runs continuously and drives a clutch,
which is in decoupled state by default. As soon as an input character is
available, the electronics of the main body will activate the
solenoid (Y1),
which in turn couples the clutch. Once coupled, the motor drives
the main axle that causes the pin-wheels and rotors to step.
At the bottom right are two
cam wheels with normally-open switches (S1, S2)
that control the timing of the cipher unit. They inform the
main unit when a character can be encrypted, and ensure that the
clutch is disengaged after a full revolution of the main axle.
In the above diagram, the blue labels refer to the contact numbers
of the four connectors at the rear of the cipher unit.
|
A major problem with the design of rotor-based cipher machines
is the reduced reliability when the number of contact junctions increases.
In other words: machines with 10 rotors are generally cryptographically much
more secure than machines with 4 rotors, but they are mechanically less
reliable because of potential contact problems.
In early machines like Enigma K, this issue was solved
by increasing the contact pressure.
Later machines like the 9-rotor KL-7, were notorious
for their contact problems, which were partly solved by issueing special
maintenance instructions.
|
| |
58 contact junctions in the cipher rotor stack !
|
The lower half of the HSE's cipher unit (i.e. the actual scrambler), has no
less than 58 contact junctions, as illustrated in the diagram above.
All contacts are silver-plated and the cores were designed
in such a way, that sufficient contact pressure was guaranteed.
Nevertheless, the development of this machine must have been a
nightmare from a designer's point of view.
The advantage of this approach however, is that the stators bays,
act as a mechanical intermediate 'end plate' for the rotors.
This means that each rotor is embraced by two such 'end plates', and
does not have to divide the pressure of its contacts over the entire
rotor stack.
|
|
When setting the cryptographic key of the HSE, the following
key types should be discriminated:
|
- Inner key
This is the daily key, which requires both rotor covers to be
opened with the supplied physical key. It was generally set by a cipher
officer.
- Outer key
This is the message key, which can be set directly from the front panel,
without opening the rotor covers. This key could be set by the
operator.
|
The Inner Key, also known as the Daily Key, requires access to
the interior of the cipher unit, for which a physical key is required.
The upper half of the cipher unit contains 7 pin-wheels that are fixed in place.
Each pin-wheel has a number of pins that is equal to the number of
positions of that wheel. Each pin can be set to active (right) or
inactive (left). This can be done by hand. The inner key specifies
which pins are to be set to active. A '1' denotes an active pin.
The lower half of the cipher unit contains the stators and rotors.
The inner key specifies the order in which the cores are installed
in the stators and rotors. It also specifies the core's orientation
(i.e. one of 32 positions). Below is an example of a valid inner key:
|
| | 0 1 2 3 4 5 | |
| Pin-wheels | 12345678901234567890123456789012345678901234567890123 | Length |
|
|
| N1: | 10101111010001011000111101001 | 29 |
| N2: | 0001011101110100010101100010010 | 31 |
| N3: | 1001011010110110110111010100101110111 | 37 |
| N4: | 00010110110101010101101101001011000001001 | 41 |
| N5: | 0111011010110111011111110000000110101101011 | 43 |
| N6: | 01111001010101010101000111010110101110100111100 | 47 |
| N7: | 00010100101110100101100000010000001000110011101110111 | 53 |
| | |
|
| Wiring cores | __ __ __ __ __ __ __ __ | |
| Core | FZYWBSTVMXRCUQEGJAINDLKOHP | |
| Position | PUNGO3ZHRVXT5UUHWCYGJCPDAG | |
|
The horizontal lines mark the two cores that are placed inside a single rotor.
At present we don't know the exact format of the inner key.
In the example above, the pins are specified as '1' (active) or
'0' (inactive). In practice however, it is possible that only the
active pins were listed, like this:
N1: 01, 03, 05, 06, 07, 08, 10, 14, 16, 17, 21, 22, 23, 24, 26, 29
|
|
The Outer Key, also known as the Message Key, consists of the
start positions of the 7 pin-wheels and the 8 cipher rotors. It can
be set when both rotor covers are closed. In other words: it can be
set by the operator without access to the interior of the cipher unit.
A different outer key should be used for each message.
Below is an example of a valid outer key:
|
| Pin-wheels | 21 11 06 22 30 08 16 |
| Rotors | C D 3 A K M 7 B |
|
|
Below is a calculation of the number of possible settings of the HSE.
Generally speaking, the number of possible settings is not the same as the
effective key space, as there are always parameters that contribute less
to the overall strength of the cipher than other parameters.
The HSE however, does not have
the weak contributors of Enigma,
such as the ring-setting (Ringstellung),
the reflector (UKW) and the reciprocal plugboard (Steckerbrett).
The number of possible settings will therefore give a good impression of
the effective key space of the HSE.
|
| Inner key | Possible settings | Result | |
| Pin-settings | 229 · 231 · 237 · 241 · 243 · 247 · 253 | ≈ 3.885 · 1084 | |
| Core order | 26! | ≈ 4.032 · 1026 | |
| Core position | 3226 | ≈ 1.361 · 1039 | × |
| | Inner settings: | ≈ 2.132 · 10150 | ≈ 499 bits |
|
|
| Outer key | |
|
|
| Pin start | 29 · 31 · 37 · 41 · 43 · 47 · 53 | ≈ 1.46 · 1011 | |
| Rotor start | 328 | ≈ 1.099 · 1012 | × |
| | Outer settings: | ≈ 1.60 · 1023 | ≈ 77 bits |
|
|
| | Total settings: | ≈ 3.41 · 10173 | ≈ 576 bits |
|
The cipher period of the machine is determined by two cycles: (1)
the pin-wheels, and (2) the cipher rotors. Let's first consider the
pin-wheels. Each pin-wheel has a different number of positions.
These are all prime numbers in order to obtain a maximum length cipher period.
As each pin-wheel makes a single step on each character, and the wheels
do not interact with each other, the cipher periode is calculated by
multiplying the number of positions of each wheel, as follows:
29 · 31 · 37 · 41 · 43 · 47 · 53
= 146,078,888,479
≈ 1.46 · 1011
(≈ 20 bits)
This means that the stepping pattern repeats after 146,078,888,479 characters.
The cipher period of the rotors is more difficult to calculate, as their
stepping behaviour is entirely controlled by the (active) pins on the pin-wheels.
In order to maximise the period, it is important that the number of active pins is
different for each pin-wheel, and that these numbers do not share a common
factor with 32 (the number of contacts of a rotor). This means that they
must be co-primes of 32.
Failure to apply the above rules, may result in a so-called weak key, in which
case the period of the cipher rotors is unknowingly shortened. It is also
possible that the initial period is a long one, but that it eventually ends
in a (repeating) short cycle which can easily be broken. It should also be
avoided to set all the pins of one or more pin-wheels to inactive.
The result would be that the corresponding rotor(s) would never move, potentially
leaving only the first rotor (R1) to step on each character.
This would reduce the cipher period to just 32 steps.
|
Although the original machines were destroyed in the early 1960s
(apart from four cipher units) and none of the circuit diagrams appear to have
survived, we have found two photographs of the interior of the Mark 1
version [1]. It is likely that these were made by T&N in or around 1955.
The first image (above) shows the device after
removing the metal cover. The upper half holds the cipher unit with the pin-wheels,
the cipher rotors and the stators, whilst the lower half holds the keyboard and two
printers: one for the ciphertext (left) and one for the plaintext (right).
Note that the front lid of the cipher unit is in one piece, whereas with the later
Mark II machine, these are two separate covers.
Furthermore, there is an extra cover over the cipher rotors (opened here).
The second photograph
(above) shows the same machine after the cipher unit has been removed.
This reveals the electronic circuit, which is built around 10 valves (tubes).
The wiring of the cipher unit is connected to the main body via
four 20-pin connectors that are visible side-by-side in the image above.
The rotors are driven by a motor which is located at the rear left
of the base unit.
|
|
Although there are no photographs of the interior of the Mark II version,
we assume that it is very similar to that of the Mark I. Its cipher unit
is slightly different — it has two seperate rotor covers that are locked with a
physical key — but its operation is functionally identical.
Instead of a keyboard and two strip printers, the lower half of the machine
holds the telex interface circuitry for connection of a
regular teleprinter, plus an interface
to the telex line or a tape puncher.
|
The cipher unit was functionally identical for both versions of
the machine. It is mechanically driven by a continuously running motor,
in combination with a solenoid-operated clutch. The clutch is activated
on each input character, which causes the cipher unit to advance to the
next state. The image below shows the cipher unit after the protective case
shell has been removed, with the pin-wheel and rotor covers open,
seen from the top. The pin-wheels are clearly visible here.
The device is built on a die-cast aluminium chassis. The upper half is taken
by the pin-wheels, whilst the lower half holds the cipher rotors. In between
them is a mechanical construction consisting of axles, cog-wheels, pawls,
sensing arms and motion arms. This construction drives the pin-wheels and
conditionally steps the cipher rotors.
The image below shows the rear side of the cipher unit, as seen from the
bottom left, whith the rotor stack clearly visible at the front.
Also visible in the above image are the four connectors that carry the
wiring to the end plates. They are placed side-by-side at the bottom edge of
the chassis. The leftmost two connectors (at the right in the image) also
carry the control signals from the two
impulse contacts
and to the solenoid
that drives the clutch.
Two resistors and a capacitor
are connected to the solenoid. This small circuit acts as a delay,
and is described in Patent DE 853,007 of 1943 [I].
The capacitor is the only component in the cipher unit
that has a date code: 75/3. It was
manufactured in week 3 of 1957, which means that it is likely that the
device was made during the course of 1957.
|
|
The rotor stack is housed in the lower half of the cipher unit and consists
of 8 rotors (with 2 cores each), 10 stators (with one core each), and two
end plates: one at the left and one at the right. All wiring cores, rotor cradles,
stator bays and end plates have 32 contact points each.
|
Unlike Enigma, the rotors are not mounted onto a common spindle.
Instead, each rotor consists of a cradle (in which the
yellow insert with the 2 cores
is placed) and two local 'end plates'. Each local end plate
forms one half of a stator bay.
A single rotor assembly can be removed from the rotor stack, by removing
two screws at the top from the adjacent stator bays,
and four screws at the bottom of the chassis.
This allows the rotor assembly to be
lifted from the stack.
A complete removed rotor assembly is shown in the image on the right.
It consists of three parts:
|
|
|
|
When we obtained the featured Cipher Unit in July 2026, it was in
unknown condition, although it was cosmetically in good shape. The pin-wheels
and the rotors could be moved by hand, but the fourth rotor (R4) did not
register (i.e. no clicks) and none of the sensing arms could be moved.
|
Furthermore, the die-cast chassis was bended inward
near connectors PL1 and PL2, which prevented them from being inserted into
the mating sockets. This was probably caused by improper handling after
the cipher units were removed from the surplus machines in the late 1960s.
As we would eventually like to get the cipher unit running again, it is
necessary to have full access to these connectors, as they carry the wiring
to the left and right end plates of the rotor stack.
The problem was solved by temporarily loosening the connectors
to get access to the edge.
|
|
|
|
Using metal plates and appropriate bending tools, the
edge of the chassis was then straightened.
The connectors are now accessible again. Mating 20-pin DIN 41622 sockets
were ordered from Reichelt in Germany. In the future this might allow
us to connect the cipher unit to a best-guess replica of the original
electronics, and eventually to an external
teleprinter and a telex line.
|
A much bigger problem are the bearings of the mechanical sensing and motion
arms inside the device. They allow the arms be mounted onto a common axle
and pivot freely against the tension of a spring. The grey tapered
bearings are made of a cast alloy, mounted at either side of the arm. In the
image on the right, three such bearings are visible below the pin-wheel.
Under the influence of temperature changes and moisture the bearings have
expanded in all directions, causing them to bind firmly onto the axle
and against the spacers in between them.
|
|
|
In addition, the cast alloy bearing has become brittle, as a result of which
it will probably break and fall apart when applying excessive force.
In total, there are 32 such bearings, divided over three axles, that are
completely blocking the mechanism. At present, this is our biggest problem.
It requires the entire cipher unit to be disassembled and alternative bearings to
be made.
To be continued...
|
- Motor and electronics missing (these are part of the machine body)
Die-cast chassis dented near connectors Right hand locking lever loose Pinout of connectors unknown - Entire mechanism blocked due to 32 bad and brittle die-cast alloy bearings
- One rotor cracked
|
- Die-cast chassis straightened out near connectors
- Right hand locking lever fixated with additional nut
- Left and right end plate wiring measured
- Wiring of all 26 cores measured
|
|
Below is the wiring of the 26 cores of the 001-series. The wiring
was measured from the cores in our collection, with the left side
defined as the input in the order 1, 2, 3, etc., and the right side
as the output. Use the diagram below as a guide. It shows the
right side of the core (the output).
This is the side that carries the series number 001 .
By assembly convention,
the top of the identification letter (e.g. the letter 'A' in the
example below) is always lined up with contact '1'.
|
| Core | 123456ABCDEFGHIJKLMNOPQRSTUVWXYZ | ← Input |
|
|
| A | RSLOX5KNY4BUGEM3VPDFITACHJ216WZQ | |
| B | PJ2IOVADGXBLFST5EJ3NR6CQUHZ14MWK | |
| C | DHIK1CLNGXQOV5J4MPRBE26AF3TUWYZS | |
| D | 5NUKVZDPGOI2AS4TWXFCJEHQRBL6Y13M | |
| E | EUAR2F4SOJL5WXNC6HMTPZ1KDVY3BIQG | |
| F | MN6DST51HFKIVLJBUWXR3EG4COYPQ2AZ | |
| G | MBG5YJHILW2SUADR3NE4CKXPFT1QVZ6O | |
| H | OALRWYPZ2QV3FS15EKTBDNXM6G4UIJHC | |
| I | GMB6A5T1RXFQNDVS4ZJLECWOPH23UYKI | |
| J | IACW6BK3VMNQRTOS1DHUEL4JF25XYZGP | |
| K | 4ODNHV2IYSXK6P5EBGLQUAM1FT3CRZJW | |
| L | VZJT6CHOAN5DGLYFBPW4I3RXKMSU2E1Q | |
| M | EJ1CGDPVH2KQ5MYNOSU36AFIBLXZRTW4 | |
| N | 56LHYDNWAIQJO1TV3KRFU2GXECP4MBSZ | |
| O | LGSKOBQW6NH5CMVAD2XZTYIU14FP3JER | |
| P | 14QE5ACKZNO3YLVSBR2PFXGTUMIWJH6D | |
| Q | IQKGJNSYFAMXU2TLBPWCZDO41E3HV56R | |
| R | 26BCE4YWNKRLFMPH1JS3GVXZADUIOT5Q | |
| S | G3CLSZEH4MD1NY6BRVF2ITUWJX5AOQKP | |
| T | 4DPALVB5QHIOSY3MJXEFRGNUZ26WK1CT | |
| U | KFRSZDTOV3J4WCIHEMNP1LQ5B6AUX2GY | |
| V | L15PZIXN4HWEKBFYM23STOG6CRAQVDJU | |
| W | JYFMNVI56ZL1T3UER2HBAKPDO4QXCSGW | |
| X | DSPX2O45HWGAFMK6EJNT13RQVCYLBIUZ | |
| Y | ERUMFI1T4PN2H5CJGSZ6ALVOW3BDKQXY | |
| Z | MITO2GCSFVDZ34KPR16YAJNXU5HLWBEQ | |
|
|
The Cipher Unit is connected to the body of the main machine via four
20-pin DIN 41622 male connectors that are located at the rear side of
the cipher unit. These connectors mate with four female connectors that
are part of the main body. Connectors PL1 and PL2 are connected to the
left end plate (input) and to the control signals
for the clutch.
Connectors PR1 and PR2 carry the lines from the right end plate (output).
The wiring of these connectors is specified below.
|
| |
Rear view of the cipher unit (bottom edge)
|
The diagram below shows the wiring order of the two end plates.
The left end plate is wired counterclockwise when observed from the left side
of the machine. The first half of the contacts (1-16, shown in red) is wired
to connector PL1. The second half (17-32, shown in blue) is wired to PL2.
The right end plate is wired clockwise when observed from the right side of
the unit. Contacts 1-16 (red) are wired to connector PR1 and contacts 17-32
(blue) are wired to PR2.
|
|
Connector PL1 is a 20-pin DIN 41622 plug.
It carries the wiring of the first half of the contacts (1-16) of the
left end plate (EL), plus the wiring to the two impulse switches
that are mounted near the clutch.
The pinout is shown when looking into the contacts of PL1.
|
| a | | b | |
| |
|
|
|
| 1. | EL 1 | 1. | EL 2 |
| 2. | EL 3 | 2. | EL 4 |
| 3. | EL 5 | 3. | EL 6 |
| 4. | EL 7 | 4. | EL 8 |
| 5. | EL 9 | 5. | EL 10 |
| 6. | EL 11 | 6. | EL 12 |
| 7. | EL 13 | 7. | EL 14 |
| 8. | EL 15 | 8. | EL 16 |
| 9. | Impuls switch S2a | 9. | Impuls switch S2b |
| 0. | Impuls switch S1a | 0. | Impuls switch S1b |
|
|
|
Connector PL2 is a 20-pin DIN 41622 plug.
It carries the wiring of the second half of the contacts (17-32) of the
left end plate (EL), plus the wiring to the
solenoid that drives the clutch.
The pinout is shown when looking into the contacts of PL1.
|
| a | | b | |
| | |
|
|
| 1. | Solenoid SOL1 | 1. | Solenoid SOL2 |
| 2. | not connected | 2. | not connected |
| 3. | EL 17 | 3. | EL 18 |
| 4. | EL 19 | 4. | EL 20 |
| 5. | EL 21 | 5. | EL 22 |
| 6. | EL 23 | 6. | EL 24 |
| 7. | EL 25 | 7. | EL 26 |
| 8. | EL 27 | 8. | EL 28 |
| 9. | EL 29 | 9. | EL 30 |
| 0. | EL 31 | 0. | EL 32 |
|
|
|
Connector PR1 is a 20-pin DIN 41622 plug.
It carries the wiring of the first half of the contacts (1-16) of the
right end plate (ER). Four pins are unused (a9, a0, b9 and b0).
The pinout is shown when looking into the contacts of PR1.
Note that the wiring is mirrored when compared to PL1.
|
| a | | b | |
| | |
|
|
| 1. | ER 2 | 1. | ER 1 |
| 2. | ER 4 | 2. | ER 3 |
| 3. | ER 6 | 3. | ER 5 |
| 4. | ER 8 | 4. | ER 7 |
| 5. | ER 10 | 5. | ER 9 |
| 6. | ER 12 | 6. | ER 11 |
| 7. | ER 14 | 7. | ER 13 |
| 8. | ER 16 | 8. | ER 15 |
| 9. | not connected | 9. | not connected |
| 0. | not connected | 0. | not connected |
|
|
|
Connector PR2 is a 20-pin DIN 41622 plug.
It carries the wiring of the second half of the contacts (17-32) of the
right end plate (ER). Four pins are unused (a1, a2, b1 and b2).
The pinout is shown when looking into the contacts of PR2.
Note that the wiring is mirrored when compared to PL2.
|
| a | | b | |
| | |
|
|
| 1. | not connected | 1. | not connected |
| 2. | not connected | 2. | not connected |
| 3. | ER 18 | 3. | ER 17 |
| 4. | ER 20 | 4. | ER 19 |
| 5. | ER 22 | 5. | ER 21 |
| 6. | ER 24 | 6. | ER 23 |
| 7. | ER 26 | 7. | ER 25 |
| 8. | ER 28 | 8. | ER 27 |
| 9. | ER 30 | 9. | ER 29 |
| 0. | ER 32 | 0. | ER 31 |
|
|
- German patent DE 853,007
Schaltungsanordung zur Verzögerung von Schaltvorgängen
Alexander Wirth on behalf of T&N, filed 19 March 1943.
Although this patent is not directly related to cipher machines, it
shows the electronic circuit that is used in the SG-39
and also in the HSE, to stretch the control pulse to the solenoid of the
clutch. This is done to bridge the time between the start signal and the
closing of the impulse contact on the machine's main axle.
- German Patent DE 974,447 — Verschlüsselungsgerät
Karl Grundlfinger on behalf of T&N, filed 15 May 1943.
This patent was filed during WWII and is related to the wartime development
of the SG-39. It has four cipher rotors, one stator,
pin-wheels, two 5-bit printers, a 32-to-5 bit encoder (diode matrix),
and a serialiser for transmission to a telex line.
Note that this (initial) design had 32 contact points on the rotors,
just like the HSE.
- German Patent DE 975,036 — Chiffriergerät
Karl Grundlfinger on behalf of T&N, filed 17 August 1952.
This patent is probably related to the wartime development of the SG-39,
as the design still incorporates a plugboard and a reflector (UKW).
It was filed after the war in 1952 however,
just before T&N started the
development of the High Speed Enigma (1953).
- German Patent DE 977,691
Chiffriergerät mit in drehbaren Kassetten gelagerten Kontaktscheiben
Werner Liebknecht on behalf of T&N, filed 1 Juni 1954.
This patent describes the basic functionality of the cipher unit of the HSE
Mark I, which is believed to be (nearly) identical to the cipher unit of the
HSE Mark II. It shows the eight rotors, the 10 stators and describes the
26 wiring cores. It also describes how seven of the rotors are driven by
the seven pin-wheels, powered by a built-in motor.
- German Patent DE 977,692 — Durchgangsscheibe für Chiffriergeräte
Franz Burkhard on behalf of T&N, filed 11 September 1954.
Addition to patent DE977691.
This patent describes the construction of the removable cores.
- German Patent DE 1,045,692 — Chiffriergerät
Karl Grundlfinger & Franz Burkhard on behalf of T&N, filed 16 August 1952.
This patent shows the combined use of cipher rotors and pin-wheels, and also the use of
a mechanical 5-bit encoder for the keyboard.
It is probably related to the wartime development of the SG-39,
as the design still incorporates a plugboard and a reflector (UKW), which
were omitted from the later HSE.
It was filed after the war in 1952 however,
just before T&N started the
development of the High Speed Enigma (1953).
- German Patent DE 1,051,543 — Chiffriergerät
Franz Burkhard on behalf of T&N, filed 1 September 1954.
This is an addition to the previous patent (DE1045692).
It was filed during the development of the HSE.
It describes in detail how the inactive pin of a pin-wheel is sensed and how
it affects the stepping of the corresponding cipher rotor.
This sensing mechanism is used in the HSE.
- German Patent DE 1,087,162
Schaltungsanordnung für Fermschreibsender mit Verschlüsselungs-Einrichtingen
Julius Sesselmann on behalf of T&N, filed 4 July 1959.
This patent describes a circuit that allows all characters of the
5-bit ITA-2 alphabet to be used for encryption,
including the NULL character (which by its nature has no active bits).
- German Patent DE 1,087,163
Schaltungsanordnung für Verschlüsselungsgeräte
Harald Fuhrmann on behalf of T&N, filed 1 August 1959.
A filter is described which suppresses impulses
on the transmission line of a cipher machine that can reveal the
plaintext of the encrypted message. This type of compromising emanation
is known as TEMPEST. The date of the application (1959) suggests
that this problem was detected after the machines had been
released (1957). Around the same time, this problem was also
discovered with other cipher machines, such as the
Ecolex II.
- German Patent DE 1,101,027
Scheibenförmige Kontaktvorrichtung für elektrische Chiffriergeräte
Franz Burkhard on behalf of T&N, filed 16 August 1952.
This patent is probably related to the SG-39, but was filed after
the war in 1952, just before T&N started the development
of the High Speed Enigma (1953). The patent describes a removable cipher rotor
with 26 contact points (A-Z), which is also shown in patent
DE 1,045,692 that was filed the same day.
- German patent DE 1,110,209 — Schaltungsanordnung zur Verhinderung einer Abhörmöglichkeit von Klartextzeichen bei Verschlüsselungsgeräten
Harald Fuhrmann on behalf of T&N, filed 24 July 1959.
This patent proposes a further solution to the TEMPEST-problem
described in German Patent DE 1,087,163 (1 August 1959).
As it appears to be difficult to fully filter out the plaintext impulses
on the transmission line, it is proposed to mask these pulses by
injecting transient noise from the machine's motor directly into
the transmission line.
- French Patent FR 1,217,625 — Dispositif de chiffrage
Telefonbau und Normalzeit
T&N (no inventor listed), filed 7 March 1957.
This patent describes a fairly complete HSE with cipher rotors, stators
and pin-wheels, but with lamps instead of the printer(s).
It appears to be a collection of previous German patents related to the HSE.
With many detailed drawings.
|
- High-Speed Enigma
- T&N High Speed Enigma
- T&N Enigma
- HSE
|
| • | 005 | Cipher unit Mk II | Private collector, Germany |
| • | 007 | Cipher unit Mk II | Crypto Museum, Netherlands |
|
- Klaus Kopacz, Cipher Unit and photographs of T&N High Speed Enigma - THANKS !
Crypto Museum, Friedrichshafen (Germany), June 2026.
- Wikipedia (Germany), Tenovis
Accessed 20 June 2026.
- Peter F. Müller, Michael Mueller and Erich Schmidt-Eenboom, Gegen Freund und Feind
ISBN 978-3498044817. Rowohlt, 13 September 2002. p. 363.
- Charles E. Chambers, Intelligence Report: Visit to Dr. Grimsen
Army Security Agency Europe, 15 November 1954. SECRET
Partly declassified by NSA on 2014-06-02 (E.O. 13526).
- Charles E. Chambers, Intelligence Report: Visit to Weintraud
Army Security Agency Europe, 2 February 1955. TOP SECRET
Partly declassified by NSA on 2014-06-03 (E.O. 13526).
- Joseph A. Meyer, Der Fall Wicher: German Knowledge of Polish Success on ENIGMA
NSA, TOP SECRET UMBRA. p. 12.
Declassified by NSA on 2007-10-31 (E.O. 12958).
- David P. Mowry, German Cipher Machines of World War II
NSA, Center for Cryptologic History. Revised 2014.
- BND, Beitrag des Leiters der Fernmeldeaufklärung (Erfahrungsbericht Schwarz) 1
Chapter IV: ZENTRALSTELLE für das CHIFFRIERWESEN.
Pullach, 1960. Streng Geheim (Top Secret). pp. 51-56.
See note 1 below.
- German Patent DE 554,421 — Elektrische Chiffriervorrichtung
Filed 31 January 1928 by Chiffriermaschinen AG, Berlin.
- Frank Raven to William Friedman, West German use of CX-52
NSA memorandum, 6 December 1954.
- Philips Ecolex II TEMPEST problems (Dutch)
Crypto Museum 2025.
|
 |
|
The following people have contributed to the content of this page:
|
|
|
- Klaus Kopacz
- Frode Weierud
|
- Erich Schmidt-Eenboom
- Peter Müller
|
|
|
|
Any links shown in red are currently unavailable.
If you like the information on this website, why not make a donation?
© Crypto Museum. Created: Saturday 20 June 2026. Last changed: Saturday, 15 August 2026 - 20:57 CET.
|
 |
|
|
|
|
|
|
|
|
|
|
| | |