Showing posts with label Hagelin. Show all posts
Showing posts with label Hagelin. Show all posts

Thursday, July 11, 2024

The American M-209 cipher machine

At the start of WWII, the US armed forces used various means for enciphering their confidential traffic. At the lowest level were hand ciphers. Above that were the M-94 and M-138 strip ciphers and at the top level a small number of highly advanced SIGABA cipher machines.

The Americans used the strip ciphers extensively however these were not only vulnerable to cryptanalysis but also difficult to use.  Obviously a more modern and efficient means of enciphering was needed.

At that time Swedish inventor Boris Hagelin was trying to sell his cipher machines to foreign governments. He had already sold versions of his C-36, C-38 and B-211 cipher machines to European countries. He had also visited the United States in 1937 and 1939 in order to promote his C-36 machine and the electric C-38 with a keyboard called BC-38 but he was not successful (1). The Hagelin C-36 had 5 pin-wheels and the lugs on the drum were fixed in place. Hagelin modified the device by adding another pin-wheel and making the lugs moveable. This new machine was called Hagelin C-38 and it was much more secure compared to its predecessor.

In 1940 he brought to the US two copies of the hand operated C-38 and the Americans ordered 50 machines for evaluation. Once the devices were delivered, they underwent testing by the cryptologists of the Army’s Signal Intelligence Service and after approval it was adopted by the US armed forces for their midlevel traffic. Overall, more than 140.000 M-209’s were built for the US forces by the L.C. Smith and Corona Typewriters Company. (2)


The American version of the Hagelin C-38 was called Converter M-209 by the Army and USAAF and CSP-1500 by the Navy. Compared to the original version it had a few modifications. The M-209 had 27 bars on the drum while the C-38 had 29. Another difference was that the letter slide was fixed. During operation the text was printed by setting the letter spindle on the left to the desired letter and then turning the hand crank on the right.

The M-209 was a medium-level crypto system used at Division level down to and including battalions (Division-Regiment-Battalion) (3) and even up to Corps for certain traffic. The USAAF used it for operational and administrative traffic and the Navy aboard ships. SIGABA was used for higher level messages (Army-Corps-Division) and hand systems like Slidex and the Division Field Code used for tactical messages (Battalion-Company-Platoon).

The Germans called it ‘AM 1’ (Amerikanische Maschine 1) and the Japanese ‘Z code‘.

Monday, June 3, 2013

German interest in Portuguese cipher machines

The cipher machines of Boris Hagelin were an alternative to the Enigma and in the 1930’s and 1940’s many countries bought them.

In 1944 the Germans had a chance to examine Hagelin machines purchased by Portugal. There were 24 large and 30 small machines being flown from Sweden to Portugal.

These were examined on 11 January 1944 at Tempelhof airport by Dr Erich Huettenhain (chief cryptanalyst of OKW/Chi), Dr Karl Stein (a member of the cipher security department) and Rotscheidt (an engineer in charge of development of cryptanalytic machinery)


 Source: TICOM report D-60 ‘Miscellaneous Papers from a file of RR Dr. Huettenhain of OKW/Chi’, p2-3

Friday, November 2, 2012

Swedish Army codes and Aussenstelle Halden

During WWII Sweden was neutral but maintained close economic relations with Germany. The German signal intelligence agencies were interested in Swedish communications and they tried to solve their diplomatic and military systems.

Diplomatic systems

The Swedish diplomatic traffic was mainly enciphered with Hagelin cipher machines. The Germans analyzed the traffic but according to postwar reports could not solve it (although one message of 5.000 words may have been solved).

The Allies also targeted Swedish Hagelin traffic and had some success, mainly through physical compromise, but according to a report dated August 1944 (Fish notes report 102) ‘the keys have not been broken since January 1942 and none of this traffic has been read since June of that year’.


Military systems

The military traffic was intercepted and decoded successfully by a unit in Halden, Norway. This was outstation Halden (Aussenstelle Halden). This unit belonged to Feste 9 (Feste Nachrichten Aufklärungsstelle -Stationary Intercept Company) but was attached to the Halden Police battalion for administrative purposes. It was commanded by Lieutenant Thielcke.

The systems solved by the Germans were:
1). SC2 - Slidex type system, read in May ’43.

2). SC3 - 3-letter field code without reciphering, read in April ’43.

3). SC4 - 3-letter alphabetical code without reciphering, read in June ’43.
4). SRA1 and SRA5 - Grille/Stencil systems. First broken in the spring or summer of ’43.

5). SM-1 (Schwedische Maschine 1) - version of the Hagelin C-38. This was solved on operator mistakes and ‘depths’. Some details are given by Luzius, an expert on Hagelin cipher machines at the German army’s signal intelligence agency:
‘7. He was then asked whether they had achieved any other successes with this type of machine. He recalled that the Hagelin had been used by the Swedes, in a form known as BC-38. This was similar to the M-209, but with the additional security feature that, whereas with the American machine in the zero position A = Z, B = Y, etc., In the Swedish machine the relationship between these alphabets could be changed. He could not remember whether it had changed daily or for each message. He himself had worked on this machine and had solved a few messages. It had been an unimportant sideline, and he could not remember details; he thought that it had been done by the same method, when two messages occurred with the same indicators. This had only happened very rarely.

The report E-Bericht 7/44 of Feste 9 has some information on Swedish systems:





The people of Aussenstelle Halden were not successful with all the Swedish codes. According to ‘European Axis signals intelligence’ vol4 the high level grille HCA and the ‘large’ Hagelin (probably a version of the Hagelin B-211) were not solved.
The solution of the tactical codes and the C-38 allowed the Germans to build up the Swedish army’s OOB. Why were the Germans so interested in the army’s dispositions? It seems that in 1943 they contemplated an attack on Sweden.

Sources: European Axis signals intelligence’ vol4, CSDIC/CMF/Y 40 - 'First Detailed Interrogation Report on Barthel Thomas’, TICOM reports I-55, I-64, I-211, ‘Hitler’s war’, E-Bericht Feste 9 - 7/44

Thursday, June 14, 2012

The Soviet K-37 ‘Crystal’ cipher machine

The Soviet Union used during WWII a large number of 2,3,4 and 5-figure codes of various types. These were all hand systems. When it came to machine ciphers they had in 1941 three different machines in service, the K-37 ‘Crystal’ off-line machine and the M-100 and B-4 cipher teleprinters.

The K-37 was a copy of the Hagelin B-211 with Cyrillic characters on the keyboard. According to cryptomuseum.com before the outbreak of WWII, Boris Hagelin was forced (by the Swedish authorities) to sell two B-211 units to the Russian Embassy. The Russians took the design and copied the machine. At the same time they converted the 5 x 5 matrix into a 5 x 6 one, in order to accommodate more characters. It allowed 30 letters of the Cyrillic alphabet to be used.

According to a very interesting article in agentura.ru production started at Leningrad plant No 209 in 1940 and by the summer of ’41 roughly 150 K-37 machines were in use.

The Germans were able to capture one K-37 machine in 1941 and they evaluated its security. They found that it had low security and could be solved on a 10-letter crib.
The war diary of Inspectorate 7/VI shows that in August ’41 a captured Soviet cipher machine was examined by the cryptanalysts Pietsch, Denffer and Hilburg and a report was prepared.



In September the analysis of the device was complete:

 
A detailed evaluation of the K-37 is available from TICOM report DF-217 ‘Russian cipher device K-37’, written by dr Grimmsen.



The device was ‘well built from the view of construction’ but the cryptographic security was ‘only conditionally sufficient’. According to a captured report from September 1941 it had not been put into use at that time but the goal was for it to replace all other cipher systems. 




From the TICOM reports it seems that the Germans never had the chance to try their theoretical solutions on actual traffic, as the machine was not used by the Soviet forces in the West.
This is confirmed by the war diary of Inspectorate 7/VI, since no further references to the K-37 can be found, apart from a study in October 1942 on intercepted messages that reached the conclusion that they were not enciphered on the K-37.


Information from TICOM reports:

From TICOM I-2 ‘Interrogation of Dr. Huettenhain and Dr. Fricke at Flenshurg,21 May 1945’, p1-2

Q. DID THE RUSSIANS USE MACHINES?
A. THEY HAVE A MACHINE MODELLED AFTER THE FRENCH PATTERN 211, HAGELIN TYPE.

Q. DID YOU HAVE ANY SUCCESS WITH THIS MACHINE?
A. WE CAPTURED A MACHINE BUT DID NOT INTERCEPT ANY TRAFFIC.

From TICOM I-64 ‘Answers by Wm. Buggisch of OKH/Chi to Questions sent by TICOM’, p4
K-37:

This was an electrical machine, almost exactly similar to the French B 211 but without the "Ueberschluesseler"(added E. wheel at one point) of the B211. It was considerably less secure than the B211 and a theoretical solution was worked out which did not need much text. B. had forgotten the details on this. The K37 had been captured, but never really used by the Russians.
From TICOM I-58 ‘Interrogation of Dr. Otto Buggisch of OKW/Chi’, p5

K-37 - A Russian machine, same principle as B211, but more primitive model was captured in 1941, and a theoretical solution worked out by HILBURG and Dr. V. DENFFER. They found it could be solved on a 10 letter crib. The work remained purely theoretical as no traffic in the machine was ever received.
From TICOM I-92 ‘Final Interrogation  of Wachtmeister Otto Buggisch (OKH/In 7/VI and OKW/Chi)’, p4

10. K-37 differed from B211 in lacking the "Surchiffreur", or ‘’Ueberschluesseler’’, a sort of Enigma wheel by which the path of the current was turned to another channel at one point, crossing  over and exchanging positions with another path instead of continuing parallel. Buggisch called this an X effect, and said it greatly complicated analysis, as it was hard to tell when it was being employed in place of the parallels.

Perhaps the K-37 was not used in the Western areas of the Soviet Union because its low security had been discovered by Soviet cryptologists or they learned that one of their machines had been captured and suspected that the Germans had found a solution.
However the German assertion that the Russians never used the K-37 is not correct. It was definitely used in the Soviet Far East in 1945. The Americans intercepted this traffic. It seems reasonable to assume that the K-37 was also used prior to ‘45 in the Soviet Far East.

Postwar history
The captured German K-37 was apparently handed over to the Western Allies at the end of WWII. The Americans built an analog model of the K-37 which they called Sauterne Mark I.

This machine was attacked after the war by the Anglo-American codebreakers. It was used on Red army circuits in the Far East.
In February 1946 US cryptanalysts managed to reconstruct its internal settings, in March the first message was decoded and by April a regular supply of decrypts was being produced.

The US success was short-lived as K-37 traffic dried up by 1947.
Sources: ‘The Secret Sentry’, agentura.ru, various TICOM reports, Intelligence and National security article: ‘Behind Venona: American signals intelligence in the early cold war’, ‘The Russian Target’ by Matthew M. Aid, cryptomuseum

Friday, June 1, 2012

The American M-209 cipher machine


This essay has been superseded by The American M-209 cipher machine - 2024


At the start of WWII the US armed forces used various means for enciphering their confidential traffic. At the lowest level were hand ciphers. Above that were the
M-94 and M-138 strip ciphers and at the top level a small number of highly advanced SIGABA cipher machines.

The Americans used the strip ciphers extensively however these were not only vulnerable to cryptanalysis but also difficult to use.  Obviously a more modern and efficient means of enciphering was needed.
At that time Swedish inventor Boris Hagelin was trying to sell his cipher machines to foreign governments. He had already sold versions of his C-36, C-38 and B-211 cipher machines to European countries.

In 1940 he brought to the US a copy of his C-38 device. This was tested by American cryptologists and it was adopted by the US armed forces for their low/mid level traffic. Overall more than 140.000 M-209’s were built for the US forces.
The American version of the C-38 was called M-209 and had a few modifications compared to the original version. The M-209 had 27 bars on the drum while the C-38 had 29. Another difference was that the letter slide was fixed. During operation the text was printed automatically.

Wednesday, April 25, 2012

ULTRA intelligence and Rommel’s convoys

One of the most important questions regarding the war in North Africa, during WWII, is what effect did the sinking of Axis convoys have on the overall campaign.

Can Rommel’s defeat be attributed to his lost supplies? Or were the losses tolerable?
It is an important question not only in the context of military operations but also because the intelligence that allowed the Allies to monitor the convoy movements came from decoding Italian secret communications. Specifically messages enciphered by the Italian Navy’s Hagelin C-38 cipher machine.
As such many authors and even the British official history ‘British intelligence in the Second World War’ mention this achievement in glowing terms and argue that it was of immense importance.
Is that true? Did Bletchley Park’s success with the C-38 have strategic implications?
The answer is yes and no.
It is undoubtedly true that the movements of the  Italian convoys could be followed by decoding their messages. For anyone who doubts that ‘British intelligence in the Second World War’ vol2 has an entire appendix ( Appendix 17-‘Contribution of Sigint to Axis shipping losses on North African route June to October 1942’ ) which lists Axis shipping sunk and the decoded messages that betrayed their journey.
The main source of information came from decodes of the C-38 cipher machine. This was a model built by  the Hagelin company and sold to many countries around the world. During WWII several countries used it for secret messages, including Italy, Portugal, Sweden and the USA. In American service it was called M-209 (slightly modified version).
The C-38 was a small but surprisingly powerful cipher provided that it was used well. If the internal settings were changed each day and if messages with the same indicator were avoided then it was very hard to ‘break’.
Unfortunately for the Axis it seems the Italians seriously misused it and thus made the British work much easier. According to a British report : ‘The very serious mis­use of it - monthly change of internal set-up, and change of slide about twice a week - robs it entirely of security’ [Source: J. J. Eachus, memorandum (nd), ‘Hagelin, as used by Italians’].
Moreover it seems that messages were frequently enciphered with the same settings so these ‘depths’ were used by the British codebreakers to recover the true settings. A ‘crib’ frequently used on those depths was ‘KSUPERMARINAKALTK’ (K was a word separator). [Source: Colossus: The secrets of Bletchley Park's code-breaking computers, Appendix 4]
In order to speed things up a cryptanalytic device named Nightingale was built and used by the British.
Thanks to these decoded messages the movements and often the contents of the convoys could be recovered in time for measures to be taken against them.
So that part of the story is clear, in which case why did i say no earlier?
Having the information is one thing. Using it is another. In order for secret intelligence to be of use in the field it is necessary for a military force to have the means to attack the enemy. In the first half of 1941 and 1942 the Brits had the information but could not attack the convoys because they lacked the necessary ships and aircraft.
Malta was used as a base for British planes and warships which attacked Axis shipping. When enough planes and ships were available they took a heavy toll on convoys. However when that happened the Germans intervened with their Luftwaffe (Fliegerkorps X  and later Luftflotte 2) and temporarily neutralised the island. This happened in the first halves of 1941 and 1942.
British efforts to move supplies and war material to Malta reversed the situation and allowed the German and Italian forces to take a heavy toll of British convoys.
Thus for long periods of time the Axis were able to transport large quantities of equipment unmolested even though their convoy routes were known to the enemy.
The other major issue is that even when the Allies made a major interdiction effort, against the convoys, the Italian Navy was able to transport the majority of supplies to N.Africa (in 1941-2)
Initially i was under the impression that the majority of supplies were sunk en route, at least that was the general impression that i got from books and articles. However a detailed look into the convoy statistics taken from the most official source ‘La Marina Italiana Nella Seconda Guerra Mondiale’-(1972) makes it clear that this was not the case.
Let’s have a look at the statistics:
Supplies by type:

Supplies by recipient:


It’s obvious that the Italians were able to transport safely the overwhelming majority of the supplies. The total is 84% for both years. This is true both for the first halves of ’41 and ’42 when the British could not effectively intervene and for the second halves when they did.
However that does not mean that the British efforts did not have an effect. There is definitely a fall in the percentages. For first half ’41 we get 94%, for second half 73%. For 1942 the numbers are 94% and 74%. If we look at specific categories then we can find cases where there is a significant drop in the supplies received.
In 1941 the main outlier are fuel shipments in November and December .During those months a British naval force operating from Malta was able to attack and destroy Italian convoys. One of their most successful operations took place on the  night of 8-9 November. As a result in November only 8% of fuel supplies are received. However due to bad luck on 18 Dec ’41 the naval K force (2 cruisers plus 2 destroyers) operating out of Malta drifted into a minefield and out of 4 ships 2 were sunk and 2 heavily damaged.
In 1942 the major German effort to neutralize Malta through bombing was successful and allowed Italian shipping to cross the Med without problems. In the second half however British efforts resumed and we can see from the stats that fuel shipments were affected. In percentage terms we get 97% for first half and 63% for the second. If we look at absolute numbers it’s 134,585t versus 113,559t, a decrease of 16%. This doesn’t seem to me to be a loss of strategic proportions.
Especially in the period July-November 1942 an average of 22,300t of combustible liquids are successfully transported. These would be enough for the Axis forces if they had chosen a defensive strategy and stayed close to their supply ports.
It should also be made clear that when books conflate lost with not arrived (as in ‘British intelligence in the Second World War’ vol2, p422) they are making a big mistake. Not arrived ≠ lost. Convoys were often ordered to return to port when ships or planes had revealed their position.
I hope that from the information presented so far it is realised that Rommel’s eventual defeat cannot be attributed to inability of the Italian navy to transport his supplies. The numbers are clear. Instead the main problem for the Germans was their inability to supply their forces far from their supply ports (mainly Tripoli and Benghazi). This problem has been analysed quite extensively by the renowned military historian Martin van Creveld in ‘Supplying War: Logistics from Wallenstein to Patton’.
German efforts to shift the blame for their defeat in N.Africa to their Italians allies were ungentlemanly.
Despite their faults the Italians fought as well as could be expected from them .The Italian Navy especially managed to transport the war supplies to N.Africa and fought with distinction throughout the campaign.
In the end the solution of the C-38 was a major advantage for the Allied side. Misused by the Italians it supplied first rate intelligence on the convoy routes. However that information did not have strategic consequences, as the British forces could not mount an effective interdiction campaign for long periods of time and even when they did most of the supplies always got through.
Acknowledgements: I have to thank Andreas Biermann for the convoy data and Ralph Erskine for giving me the information concerning British efforts vs the Italian C-38.

Tuesday, January 3, 2012

Last minute compromise of operation Dragoon

In summer 1944 the Western Allies invaded France. The first operation was codenamed Overlord and took place on 6 June ’44 in the Normandy area.

Operation Dragoon followed on 15th August ’44 in the South of France.

In my post on French Hagelin cipher machines , there was a statement by cryptanalyst Buggisch of the Army’s Signal Intelligence agency Inspectorate 7/VI , [Ticom I-92,p3] : ‘’ ……. Buggisch spoke especially of the successful solution of C36 in 1943, on de GAULLE traffic to CORSICA. He also said that the Southern France landings were largely given away as to date and strength of force by broken C36 traffic.’’

Buggisch was telling the truth. From HW 40/7 ‘’ German Naval Intelligence successes against Allied cyphers, prefixed by a general survey of German Sigint’’ , p29 :

In the Mediterranean area the Germans continued to derive a certain amount of information from low grade French traffic. On 11th August, 1944 a German Army B reports seen in Special Intelligence quoting a Free French signal, thought to be made in Hagelin, which gave details of the allocation of shipping space for the eminent Allied landing in Southern France. The time lag in issue was only about 10 hours, and on the basis of this B-report the German Admiral commanding South coast of France was warned on 14th August of the probability of a landing in his area in the near future .

Tuesday, December 20, 2011

French Hagelin cipher machines

During the 1930’s and 40’s the military and civilian authorities of many countries began to purchase and use cipher machines in order to secure their confidential radio traffic. Cipher machines were more secure than the book systems that they replaced and they encoded/decoded faster. The main players in the international market were the well known Enigma machine in its commercial version and the products of Boris Hagelin, mainly the ‘small Hagelin’ C-36 and ‘large Hagelin’ B-21/211.

French Army codes and ciphers

The French military and civilian authorities used for their secret communications several codebooks, both enciphered and unenciphered. Individually these systems did not have a very high degree of security but it seems that the French strategy was to overwhelm enemy codebreakers through the simultaneous use of a large number of different codebooks (1). Additionally, it is possible that the French Army’s cipher bureau overestimated the security of the encipherment procedures used with the codebooks.

The French Army acquired cipher machines in the second half of the 1930’s, specifically the Hagelin models C-36 and B-211. By 1939 there were about 2.000 C-36 and 115 B-211 machines in use. The B-211 was used at the level of Army Corps and by the High Command. The C-36 was used as a mid level cipher for Armies and Divisions in France and N. Africa (2).

The B-211 and C-36 continued to be used by the Free French Forces during the period 1942-45 in N. Africa and Italy. However, from 1943 the C-36 was gradually replaced by the US M-209 cipher machine (3). 

German solution of French Army cryptosystems

According to the available information the B-211 machine proved secure during the period of the Phoney war and the Battle of France. On the other hand C-36 machines were captured and by July ’40 that traffic was read (4).

After hostilities ended the cryptanalysts of the German Army’s signal intelligence agency Inspectorate 7/VI (later OKH/GdNA) managed to acquire these cipher machines and they found ways to retrieve the internal settings and read this traffic. Initially their research was only of a theoretical character since no new traffic was being intercepted on these systems. However once the Free French forces of General De Gaulle started using them again in 1942 they were in a position to benefit from their earlier research.

In the case of the C-36 the methods of solution were successful against field traffic in the period 1942-45. Messages of the large Hagelin B-211 however could not be solved. The reason was that the French had anticipated the German efforts to read their codes so they physically modified the B-211.

Thanks to the solution of the C-36 the Germans were able to decode French traffic in North Africa and Italy in the period 1942-44. The Anglo-American authorities however were aware of the insecurity of French codes so they provided the M-209 (American version of Hagelin C-38) to the French forces fighting in Italy. The Germans were also able to read traffic on this system but not as much as they had with the C-36. The M-209 was an inherently more secure cipher machine (6 wheels instead of 5 in the C-36). (5)

Apart from the Army agency In. 7/VI the Signal intelligence agency of the Supreme Command - OKW/Chi seems to have successfully solved the C-36, however not many details are known about their work. The methods of solution are given in Ticom I-45 ‘OKW/Chi Cryptanalytic research on Enigma, Hagelin and Cipher Teleprinter machines’ (6) 
Overview of German exploitation of French cipher machines
Information on the German exploitation of French Hagelin cipher machines is available from various TICOM reports (7) and from the War diary of Inspectorate 7/VI.

A summary is given by colonel Mettig, head of In. 7/VI from November 1941 to June 1943. From TICOM I-78 ’Interrogation of Oberstlt Mettig on the History and Achievements of OKH/AHA/ln 7/VI’, p4 and 9

France
With the opening of the offensive in May 40, the French began to use ciphers in increasing quantities. The Germans soon felt an acute shortage of forward cryptographers and were therefore unable to undertake much work on the French forward ciphers. As a result, the forward units concentrated on the two French cipher machines, the B-211 and C-36. Progress was slow, but as a result of research on two captured C-36 machines, Army Group C was in a position, by Jul 40, to undertake satisfactory reading of the traffic. Likewise it was impossible to break the B-211 machines in time for that information to be of any value. Nevertheless the research undertaken during this period was to justify itself later.



Referat France
This section lost a lot of its importance after the campaign of 1940. It concentrated on watching the communications of the VICHY Government which was supposed to inform the Germans of their cipher procedures. Breaches of regulations committed by the French were reported to the Disarmament Commission at WIESBADEN and rectified. The retention of captured French documents and the further investigation of the French cipher machines C-36 and B-211 justified itself in that the initial de Gaullist WT traffic in NORTH AFRICA for 1942-43 was undertaken through those methods. It was possible to read all these techniques at the start but how far the success was maintained during 1943 PW cannot say.



These statements can be verified from the war diary of Inspectorate 7/VI.

Hagelin C-36 and C-38 (M-209)
The monthly reports show that in 1941 the C-36 device was extensively investigated and methods of solution found. The methods were refined to the extent that even small messages could be solved.

Report of May 1941:

Report of June 1941:


According to the Army cryptanalyst dr Otto Buggisch (8) the methods of solution were:

C-36 - The theoretical analysis of this in 1940 developed two theoretical methods.
1) Based on frequency of K. as word separator.

2) Statistical - various, depending on the most usable feature of the traffic, low, high letters, etc. The studies made by B. et al. were used by Oberinsp. Kuehn to forestall the introduction of the device into the German Army, as advocated by Major JUNG.
B. says the statistical method was later used in practice and needed 300 letters. He makes general statements about considerable later success with C-36, from 1942 on. (Not pinned down on this.)

In late 1942 French radio traffic on the link Algeria-Morocco was identified as being enciphered on the C-36 and thanks to the previous studies these messages were solved. In German reports the French C-36 was identified as procedure F-19.
Report of December 1942:


In January the internal settings of the C-36 and the indicator system were changed but in February they were solved and for the period March - December 1943 the process could be read continuously with the results communicated quickly to KONA 7 (Kommandeur der Nachrichtenaufklärung - Signals Intelligence Regiment), based in Italy.

Report of May 1943:



By the summer of ’43 KONA 7 could handle the solution of the C-36 with In. 7/VI only processing corrupted messages that did not decode properly. The traffic solved was from N. Africa and had the indicators xab and fva. In October 1943 messages between Algiers and Corsica were also read. In December the traffic dropped off and the Germans suspected that the US M-209 cipher machine had been introduced in French networks.

They weren’t wrong, since according to a British report (9) in early 1944 the US military supplied M-209 machines to the French Forces fighting in Italy. The M-209 was much harder to solve than the C-36 since the internal settings could only be retrieved by finding messages in depth.


However the C-36 continued to be used by French forces and their traffic could be solved. In the first half of 1944 a new indicator procedure hindered the German efforts and messages had to be attacked individually. Information on the new indicator is given by Buggisch in TICOM I-92 ‘Final Interrogation of Wachtmeister Otto Buggisch (OKH/In 7/VI and OKW/Chi)’, p3
3. Complications in C36. Buggisch could recall no ‘complicated enciphering device’, unless he had meant to refer to the new indicator method introduced in January of 1944. The old indicator system, changed in its details in 1942, had been a letter substitution table, which had been simple. The new system was based on numbers, but he could give no details. Relative internal settings continued to be recovered and a high percent of the traffic solved on cribs and statistics (for any message over 400 letters) until the indicator system was broken in the late summer of 1944. About the same time in 1944 the French had adopted a system of sending internal settings by mean of an ordinary sentence for each wheel, of which the first so many non repeating letters gave the active lug positions. This system was first reported in a broken code message; the knowledge that it existed was of academic interest only, as no keys wore gained from other systems.

Buggisch spoke especially of the successful solution of C36 in 1943, on de GAULLE traffic to CORSICA. He also said that the Southern France landings were largely given away as to date and strength of force by broken C36 traffic.
In June and July 1944 the indicator system was completely solved and the traffic of the previous months decoded. The statement by Buggisch on operation Dragoon can be confirmed in part by British report HW 40/7 ‘German Naval Intelligence successes against Allied cyphers, prefixed by a general survey of German Sigint’, p29

In the Mediterranean area the Germans continued to derive a certain amount of information from low grade French traffic. On 11th August, 1944 a German Army B reports seen in Special Intelligence quoting a Free French signal, thought to be made in Hagelin, which gave details of the allocation of shipping space for the eminent Allied landing in Southern France. The time lag in issue was only about 10 hours, and on the basis of this B-report the German Admiral commanding South coast of France was warned on 14th August of the probability of a landing in his area in the near future.


The German army’s codebreakers continued to solve the C-36 settings till the end of the war.

Hagelin B-211
The ‘large Hagelin’ B-211 was also investigated by the Germans and in December 1941 a breakthrough was made in the solution of the device.

Report of December 1941:


In 1942 research continued and frequency counts were made on the solved messages from past traffic. However in late 1942, when French traffic from N.Africa was intercepted, only C-36 messages could be solved. The reasons were that only a small number of B-211 messages were intercepted and that the French B-211 had been modified in some way. The investigations on the B-211 (called procedure F-20 in the German reports) continued in 1943 and they were carried out at Referat F - Forschung (Research department).
Report of May 1943:

Eventually the German codebreakers reached the conclusion that they could only solve this traffic if they had access to a large volume of messages or captured cipher material.
Report of August 1943:

Hagelin B-211 traffic continued to be investigated during the war but no messages were solved. According to a US report from October 1944 the modified B-211 had a high level of security for the reasons identified by the German codebreakers, specifically the modifications made on the device and the low level of traffic (10).



Conclusion
In conclusion we can say that the French did not fare well in the cryptologic field during WWII .The Germans considered their methods outdated and the Anglo-Americans were constantly irritated by their security compromises (11). 




During the 1930’s and up to the Battle of France their high level codes were read by the Germans (12). In N.Africa and Italy their low and mid level codes compromised Allied plans. Moreover it seems that they continued to use weak cryptosystems even after the end of the war up to the 1960’s (13).
The best thing that can be said about the French is that although they lost the cryptologic war by facilitating the Polish success with the Enigma they fatally compromised the basis of German communications

Notes:
(1). TICOM report DF-187B, p6 and SRH-349 ‘The Achievements of the Signal Security Agency (SSA) in World War II’, p31

(2).  ‘Bulletin de l’ARCSI’ article: Bulletin N°3 1975: Essai d'historique du Chiffre (Add. N°3).

(3). ‘Bulletin de l’ARCSI’ article: Bulletin N°4 1976: Essai d'historique du Chiffre (N°5).

(4). Various TICOM reports including I-78

(5). Various TICOM reports, War diary of Inspectorate 7/VI


(7). TICOM reports I-18, I-23, I-45, I-58, I-78, I-92, I-160


(9). British national archives HW 40/258 ‘Enemy Sigint successes against Allied communications’

(10). NARA - RG 457 - Entry 9032 - box 1432 - NR4779 ‘Hagelin use by French’

(11). British national archives HW 40/258 ‘Enemy Sigint successes against Allied communications’


(13). Histoire de la machine Myosotis


Solution of the Hagelin C-36 at OKW/Chi:

The Hagelin C-36 cipher machine was not a secure device and it seems that in the 1930’s the codebreakers of OKW/Chi (codebreaking department of the Armed Forces High Command) developed methods of solving it.

According to the NSA report ‘Regierungs-Oberinspektor Fritz Menzer: Cryptographic Inventor Extraordinaire’, p21 in 1936 Fritz Menzer developed two methods for solving the C-36.

Also in TICOM report I-31, p7 dr Huttenhain (chief cryptanalyst of OKW/Chi) stated that the French C-36 type could be solved cryptanalytically (without the use of stereotyped beginnings).

Unfortunately, there is no information on the work they did on the C-36 during the late 1930’s and in 1940. Considering their statements on the security afforded by the device it is possible that at OKW/Chi some French Hagelin C-36 traffic was solved during that time.

Update: A detailed history of the French Hagelin C-36 and its indicator system is available from Jean-François Bouchaudy  - French Army C-36 cipher machine.