Wednesday, July 9, 2014

The French War Ministry’s FLD code

In May 1940 Germany shocked the world by defeating the combined forces of France, Britain, Belgium and Holland in a short land campaign. Unlike World War I that had ended in millions of deaths and a stalemate in the West, this time the German forces were able to quickly defeat their opponents. After France’s defeat several theories were promoted, trying to explain this strange outcome. Some focused on the supposed superiority of the Germans in manpower and armaments, while others tried to point to the German Panzer divisions that supposedly had a big advantage over the similar French units.

General Gamelin who commanded the French forces told Churchill that the defeat was due to: ‘Inferiority of numbers, inferiority of equipment, inferiority of method’. In fact both sides had roughly similar strength in troops and aircraft while in tanks it was the Franco-British alliance that had the advantage, both in terms of numbers and of quality.
However the German were able to overcome their tank inferiority by grouping their armored divisions together, supporting them with ample airpower and providing them with dedicated infantry, anti-tank, artillery and communication units. At the same time their radio communications system was much more advanced than the French Army’s and orders could be dispatched quickly and securely to all units.

The German leadership also took a big risk by attacking through the Ardennes area with the purpose of cutting off the northern part of the Allied front.
Another area where the Germans had the advantage was in signals intelligence. Unfortunately historians have focused almost exclusively on the German Enigma cipher machine and its solution by the codebreakers of Bletchley Park thus neglecting the many successes of the German codebreakers 

The German victories during the period 1939-1942 in France, N.Africa, Atlantic and in the Eastern Front were achieved at least in part thanks to their ability to read their enemies communications.
French military codes and the Battle of France

The French military and civilian authorities used for their secret communications several codebooks, both enciphered and unenciphered. Individually these systems did not have a very high degree of security but it seems that the French strategy was to overwhelm enemy codebreakers through the simultaneous use of a large number of different codebooks (1). Additionally, it is possible that the French Army’s cipher bureau overestimated the security of the encipherment procedures used with the codebooks.

According to the available sources the following cryptosystems were in use in 1939 (2):

For high level networks (Army High Command and Army Corps) the machine cipher B-211 and 5-figure/5-letter dictionaries enciphered with transposition methods.

For mid level networks (Armies and Divisions) the machine cipher C-36 and the 4-figure/4-letter codebooks RA, ATM and 69.

For low level networks (small Army units like battalions and regiments) codebooks enciphered with short additive keys (9-13 digits long) plus 3-letter dictionaries.

From recently released TICOM reports and various books it is clear that the Germans could read French Army tactical codes (3), the Navy’s main cipher system (4) and the Airforce’s ‘Aviation Militaire’ (5). By exploiting these systems the Germans obviously got valuable intelligence. However their main success that directly contributed to their victory in 1940 was achieved against a high level enciphered code used by the French War Ministry.

The code of the French War Ministry

From the early 1930’s the German codebreakers could read the code used between the French War Ministry and the various military districts. This was a 4-figure codebook of 10.000 values enciphered with additive sequences. In September 1939 there was a change in the method of encipherment and columnar transposition was used instead of addition. Unfortunately for the French this method had been used by one of their military districts prior to September 1939, thus allowing the Germans to solve it and figure out how the transposition keys were chosen. Thanks to this compromise the Germans could read messages of the War Ministry and the military districts till June 1940. The information gained concerned the French army’s order of battle, the weak point of the Maginot Line, the mood of the troops and the population in France and in the colonies, the order of battle of the British troops stationed on the mainland and their movements.
Information on the compromise of the FLD code is available from several sources.

Colonel Mettig, head of the German Army’s signal intelligence agency Inspectorate 7/VI in the period 1941-43, said in TICOM report I-128 ‘Deciphering Achievements of  In 7/VI and OKW/Chi’, p2
In assessing the value of Signals Intelligence PW considers that the deciphering of messages of strategic importance is more valuable than deciphering those of tactical importance. He therefore rates most highly the solution of the French ciphers in the FLD military network radiating from Paris. The deciphering of this traffic before and during the war gave a clear picture of the order of battle of the French and Belgian armies and also of the British army.

This success was accomplished by the codebreakers of the German High Command's deciphering department – OKW/Chi. Wilhelm Fenner, who was head of the cryptanalysis department of OKW/Chi, said in TICOM DF-187B, p7

‘Even before the military action with France began, the military systems of French higher staffs were solved. This was a 4 or 5-figure code that was systematically transposed (tableau carve) .In the cryptograms a few parallel passages (repetitions) were discovered .The interval between these passages was constant and must therefore correspond to the width of the transposition box as cryptanalytic studies have shown.If I am not mistaken the keys (Loesungen ?  ? ? )  ? ? the box itself were taken from the same code book. Despite all the cunning of this cryptographic system, the occurrence of short parallel passages proved fatal. By the aid of these deciphered messages tabs could be kept on the French Army far back into the homeland.’

Colonel Randewig, head of the intercept organization in the West during the 1940 campaign wrote in the report FMS P-038 ‘German radio intelligence’:
As early as December 1939 the Germans broke a special cryptographic system used by the French command in radio messages to the armies and military district headquarters. It had been used contrary to regulations prior to the opening of hostilities in September 1939. The Germans were able to solve this system because the radio station guilty of the violation was reprimanded and thereupon repeated the same messages in the proper system. Their contents revealed a certain amount of organizational information, for example, the fact that the French 2d and 3d Cavalry Divisions had been reorganized into the 1st and 2d Armored Divisions and were due to move into their assembly area northeast of Paris by 1 January 1940. However, this type of incomplete information could generally be considered only as a supplement to and confirmation of other intelligence concerning the enemy. It was not possible to deduce the enemy's order of battle from radio intelligence alone.

Nevertheless, the Germans could identify the probable concentration areas of the French and British armies from the practice messages sent by the field radio stations, although the boundaries of army groups, armies, corps and divisions could not be established with any certainty. Greater clarity prevailed about the fortified area behind the Maginot Line in the south. Enemy forces stationed near the Frenco-Swiss and Franco-Italian borders were not observed according to any regular plan. Spot-check intercepting failed to pick up the French Tenth Army in the place where it was presumed to be by the German command. However, radio intelligence did indicate the presence of the French Sixth Army.
The importance of this intelligence is even admitted by the official history ‘British Intelligence in the Second World War volume 1’, p163-4

It later became clear that, until the fall of France, Germany enjoyed not only the strategic initiative but also the advantage of good operational intelligence………. During the planning and the carrying out of the attack on France the work of the enemy intelligence department of the General Staff of the German Army was of crucial importance and its value fully justified the prestige which the department had always enjoyed. The work has been described by General Ulrich Liss, head of the department from 1937 to 1943. He emphasizes that partly on the basis of British army documents captured in Norway, which provided all it needed to know about the British order of battle, and partly from the cypher traffic between the French War Ministry and the army groups, armies and home authorities, most of which it read from soon after the outbreak of war until 10 May, the department had a very comprehensive and accurate knowledge of the dispositions and qualities of the Allied forces………… During the campaign its intelligence continued to be good, and Sigint continued to be the best source.
However the person who can give the most accurate account of the work done on the FLD code was the chief cryptanalyst of OKW/Chi, Erich Hüttenhain. According to Hüttenhain’s manuscript ‘Einzeldarstellungen aus dem Gebiet der Kryptologie‘, p14-16 (6) the code used between the French War Ministry and the military districts was a 4-figure codebook of 10.000 values, enciphered with short additive sequences. Since this method of encipherment offered limited security and the underlying code remained in use for years these messages could be read by the Germans. However a different system was used by the military district in the border with Italy. Here the code was transposed based on codewords. After finding two messages with parallel passages the German codebreakers were able to solve this system in 1938 and they realized that the transposition keys were created by using the codegroups of the codebook. Thus from mid 1939 the traffic of this military district could also be solved. In September 1939 when WWII broke out the French War Ministry instead of changing the cipher procedures, ordered that this system of transposition was to be used by all the military districts. Since the 4-figure codebook remained in use the Germans could read this traffic up to June 1940 and Hüttenhain says that the German leadership was informed of all significant operations within the French armed forces.

Among his conclusions about this case were that a country should not adopt for its main cipher a system that is already known to the enemy and thus possibly compromised and that indicator groups should be independent of the cipher.

Das französische fld-Netz 
Beim Anfang der dreißiger Jahre benutzte das französische Kriegsministerium im Verkehr mit den französischen Wehrkreisen zur Verschlüsselung der Nachrichten einen 4Z-Code, der mit einer endlichen Additionszahl überschlüsselt wurde. Fast alle 10.000 Gruppen des 4Z-Codes waren belegt. Der Code wurde im Laufe der Jahre nicht geändert oder gar abgelöst. Die Additionszahlen wurden in kürzeren Zeitabschnitten abgelöst. Es waren jeweils gleichzeitig mehrere Additionszahlen im Gebrauch. Die Längen der einzelnen Additionszahlen waren ungerade und schwankten zwischen 7 und 13 Ziffern. Die mit dieser Geheimschrift,also mit dem 4Z-Code verschlüsselten Nachrichten wurden in den letzten Jahren vor dem 2. Weltkrieg vollständig mitgelesen. In dem Verkehr mit dem an Italien angrenzenden französischen Wehrkreis verwendete das französische Kriegsminister rium ein anderes Chi-Verfahren. Im vorangehenden Studium des gesamten Spruchmaterials dieses einen Verkehrskreises wurden 2 Sprüche gefunden, die eine größere Anzahl von fast gleich langen und über die ganzen Spruchlängen fast gleichförmig verteilten Ziffernfolgen enthielten; lediglich die Reihenfolge der diese 2 Anfangszeilen bildenden Ziffernfolgen in den beiden Sprüchen war verschieden. Diese Feststellung führte zur Erkenntnis, daß ein Ersatzverfahren mit einem Würfel überschlüsselt wurde. Mit Hilfe von 2 Anfangsreihen konnte die Würfellosung rekonstruiert und das Ersatzverfahren als 4Z-Code erkannt werden.-Es war also in den beiden Sprüchen, die zum Einbruch in das Verfahren führten, eine längere, sich über mehrere Zeilen des Würfelkastens erstreckende gleiche Textstelle vorhanden.

Der 1. Einbruch gelang im Jahre 1938. Im Laufe der nächsten Monate wurden weitere dieser Parallelstellen-Kompromisse gefunden. Es wurden die in Wortlosungen umgewandelten Würfellosungen als die Klarbedeutungen der Codegruppen des verwendeten 4Z -Codes erkannt. Und es wurde erkannt, da als Kenngruppen für die Würfellosungen 4Z -Gruppen des Codes gewählt wurden, deren Klarbedeutung jeweils die Wortlosung des Würfels war. Auf diese Weise lieferten gedeutete Codegruppen neue Würfellosungen und rekonstruierte Würfellosungen neue Codegruppen. Mitte 1939 wurde der gesamte Verkehr zwischen dem französischen Kriegsministerium und dem an Italien angrenzenden Wehrkreis, der also mit der Geheimschrift 4ZCüW verschlüsselt wurde, mitgelesen.
Als am 3. September der Krieg mit Frankreich ausbrach, verfügte das französische Kriegsministerium, daß die bisher nur im Verkehr mit dem an Italien angrenzenden Wehrkreis benutzte Geheimschrift 4ZCüW unverzüglich auch in allen anderen Wehrkreisen verwendet wurde. Es blieb der Code derselbe, und es wurden die Würfellosungen nach wie vor aus den Klartextbedeutungen der Codegruppen genommen. Es wurden lediglich an den jeweils folgerden Monatsersten geringfügige Änderungen an den Kenngruppen vorgenommen, Änderungen, die in kurzer Zeit erkannt und nach einigen Wechseln sogar vorausgeahnt wurden.

Dieser Zustand blieb bis zum Ende des Frankreichfeldzuges im Juni 1940 unverändert bestehen. Jeder aufgenommene Spruch dieses militärischen Führungsnetztes, das als fld-Netz bekannt war, wurde mitgelesen. Die deutsche militärische Führung war über alle wesentliche Vorgänge innerhalb der französischen Wehrmacht unterrichtet. Neben der Gliederung in der französischen Wehrmacht klärten die mit gelesenen Sprüche die Bewaffnung der einzelnen Einheiten auf, die schwächste Stelle der Maginot-Linie, die Stimmung der Truppe und der Bevölkerung in Frankreich und in den Kolonien, die auf dem Festland stationierten englischen Truppen und deren Bewegungen usw.
Es erscheint angebracht, an Hand dieses für Frankreich und für Deutschland folgenreichen Entzifferungs ergebnisses einige Folgerungen zu ziehen:

1. Es ist falsch, ein Chiffrierverfahren, dessen Sicherheit nicht bewiesen ist, zum Hauptverfahren zu machen, wenn es bereits als Nebenverfahren als beim Gegner bekannt vorausgesetzt werden muß.
2. Ein Chiffrierverfahren, dessen Sicherheit von der Struktur der Klartexte-Anfängen, Schlüssen,  Parallelstellen, Spruchlängen u.a. - abhängig ist darf nicht verwendet werden.

3 Kenngruppen müssen vom Chiffrierverfahren unabhängig sein; sie dürfen keine doppelte Bedeutung haben.
4. Die Erfassung des Spruchmaterials sollte vollständig sein, um auch die kompromittierenden Sprüche finden zu können.

Anm.: Rekonstruierte Seite einer Kopie, deren 12 Anschläge links unlesbar waren. Hier sind also die ersten 12 Anschläge erraten,-allerdings sinngemäß! Ausnahme: Zeile 12, wo die Zahl 13 willkürlich ist,für die allerdings 2 Bedingungen stehen: 1) >7 und Zweistelligkeit (in den 12 Anschlägen).

The German victory in the Battle of France shook the world in 1940 and countless theories were formed in order to explain this unusual event. Up to 1940 the French Army was thought to be the most powerful and best equipped force in Europe. Supported by the small British Expeditionary Force, the powerful British Fleet and with military supplies coming in from the United States the Franco-British alliance had every reason to expect a victory over Germany thanks to its superior economic resources. 
The German leadership took a huge gamble by concentrating all their armored divisions and using them to encircle and destroy the northern flank of the Allies but this gamble paid off. In a victory of such magnitude it is not possible to attribute success to only one factor. Obviously the German advantages in training, doctrine, leadership, communications etc were decisive. However the German victory also owed a lot to signals intelligence and codebreaking. Especially the solution of the War Ministry’s code gave the Germans valuable information on the location of the Allied units and was obviously used during the planning stage for the attack.

(1). TICOM report DF-187B, p6 and SRH-349 ‘The Achievements of the Signal Security Agency (SSA) in World War II’, p31.

(2). Bulletin de l’ARCSI’ article: Bulletin N°3 1975: Essai d'historique du Chiffre (Add. N°3).

(3). EASI vol1 – ‘results of European Axis cryptanalysis’

(5). TICOM report I-112, p6

(6). Bayerische Staatsbibliothek: ‘Einzeldarstellungen aus dem Gebiet der Kryptologie’ - BSB Cgm 9304 a

Additional information:
The US report SRH-361 ‘History of the Signal Security Agency volume two - The general cryptanalytic problems’, p136 mentions a French cryptosystem solved in 1944 that was similar to that solved by the Germans in the 1930’s. This was a transposed code, with the transposition keys created from the codegroups of the codebook.

Link to chapter VI – ‘The French systems’ of SRH-361

1 comment: