Cryptographic history is not a parade of geniuses inventing ever more complicated symbols. As letters, telegraphy, radio, and computer networks connected distant people, what an attacker could see, which keys had to be protected, and what counted as evidence of security changed together.
QUESTION FOR THE ROUTE
As communication became faster and wider, why did secrecy become less a matter of stranger-looking ciphertext and more a redesign of what could be public and which keys had to remain private?
WHAT THIS RIVER DOES NOT CLAIM
The river is not geography. Distance downstream stands for time passing, and the light turns from dawn to dusk as the centuries go by. The objects by each stele are symbols of the kind of event and of how each century band wrote and calculated; they do not reconstruct any real artefact. The land around each stop sketches the natural geography of the scene’s real place, and an iconic building appears only if it already stood in that year. Each scene keeps its real place and evidence basis; open it on the map to read where it happened. The line is neither proof that one cipher travelled unchanged from Baghdad to Cambridge nor a ranking of wartime victory or civilizations. It is the viewer’s edited itinerary across manuscripts, diplomatic mail, print, patents, telegraphy, radio interception, classified documents, and public journals that made different attacks and defenses visible; every pin states its own location basis and limit.
WHAT YOU SEE ON THIS RIVER
- Diagram in the sky
- Letter-frequency bars — what a ciphertext cannot hide
- Emblem at the source
- A two-ring cipher disk
- The real place around each stop
- Around each stele the land takes on the natural geography of that scene’s real place — sea or lake, plain, hills or mountains, the colour of the ground and its common trees — and, where one defines the place, its landform: a volcano, snow peaks, granite domes, a mesa, dunes, a fjord, islands, a rock hill, a gorge or loess terraces. The water near the stop takes the colour of the real river or sea, and the haze the place’s climate. A small globe on the stele marks where it is, with the route from the previous place. Where a city has an iconic building that already stood in the scene’s year, its schematic silhouette rises behind the stop and is named on the card. The land follows today’s terrain and climate as a sketch and the silhouettes are not measured reconstructions. Between stops the river itself stays symbolic.
- A figure board at every stop
- Each board draws the mathematics of that scene. When the boat arrives, the construction is drawn in and the key result rises in red. The drawings are schematic reconstructions, not historical manuscripts.
- Century bands along the banks
- 500–1449 · Stone stele · paper lanterns · single-arch bridge · watermills and villages · lateen boats
- 1450–1749 · Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships
- 1750–1899 · Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats
- 1900–1969 · Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft
- 1970 onward · Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites
Where the century band changes, the boat passes under a bridge of the new band. Villages, mills, factories, pylons and towers stand for the technology of each century, not for any real place or architectural style.
01·c. 850 CE·Baghdad(basis: Composition)
Language Leaves a Fingerprint inside a Secret — Al-Kindi and Frequency Analysis
A cryptanalytic treatise attributed to al-Kindi explains counting how often each letter appears in a long Arabic text and comparing that distribution with the most common symbols in a ciphertext to infer a monoalphabetic substitution. Replacing the same letter by the same sign hides words but preserves unequal repetition in language. The surviving manuscript is not an autograph, its exact room of composition cannot be fixed, and the work should not erase earlier secret-writing traditions as one solitary beginning of cryptography.
- Pause and ask
- If every letter has been replaced by another sign, can the ciphertext alone still reveal traces of its language?
- How thinking changed
- Replacing the same letter with the same sign hides word shapes but preserves unequal letter frequencies in the language. Comparing long plaintext and ciphertext distributions turned guessing at meaning into a measurable statistical attack.
- What we cannot claim
- The c. 850 Baghdad pin is an approximate activity and scholarly-context marker. The surviving manuscript is not an autograph and does not prove an exact room, exact year, or a solitary status as the first cryptanalyst.
- This place
- Court patronage, translation and copying, language study, and administrative and diplomatic texts in ninth-century Baghdad supplied readers and varied writing against which cryptanalysis could be described systematically. This is not collapsed into one modern-style institute called the House of Wisdom. (Tigris banks · date palms · flat plain · 33.3°N 44.4°E)
- Figure board
- Letter frequencies of long plaintext (above) are compared with ciphertext sign frequencies (below); pairing them by rank infers the substitution.
- On the river
- A desk holding a written record · 500–1449 (Stone stele · paper lanterns · single-arch bridge · watermills and villages · lateen boats)
02·c. 1466 CE·Rome(basis: Composition)
Rotating Away from One Fixed Alphabet — Alberti’s Cipher Disk
Alberti described two rings of letters that could rotate into a cipher disk and a method for changing alphabets within a message. The idea unsettled the fixed correspondence that frequency analysis attacks. The treatise belongs to Alberti’s Roman activity around 1466–67 but was printed posthumously only in 1568; neither date nor one device completes every later polyalphabetic cipher.
- Pause and ask
- If frequency analysis looks for a fixed letter mapping, what happens when the mapping itself changes within the message?
- How thinking changed
- Rotating a disk changes the cipher alphabet so the same plaintext letter can receive different signs. An attacker must find switch points and several distributions, while defenders must agree not only on a key but on when to rotate.
- What we cannot claim
- The treatise belongs to about 1466–67; 1568 is its posthumous publication. Rome marks an activity context, not the location of a surviving disk or exact study, and does not make Alberti the sole inventor of every polyalphabetic cipher.
- This place
- For Alberti as papal secretary and diplomat, Rome joined confidential correspondence among rulers and cities with a humanist culture of designing mechanical devices. A request from Leonardo Dati helped turn a practical problem into a treatise. (Tiber banks · umbrella pines · hills · 41.9°N 12.5°E · landmark: Colosseum (80), Pantheon (125))
- Figure board
- Rotating the inner ring against the outer ring of letters changes the cipher alphabet, so the same plaintext A becomes different signs over time.
- On the river
- A desk holding a written record · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
03·1511 CE·Venice(basis: Main activity)
Cryptanalysis Becomes an Office and an Archive — Venice’s Diplomatic Ciphers
The Venetian Republic joined the deciphering skill of secretaries such as Giovanni Soro to the work of the Council of Ten as ambassadors, merchants, and commanders generated coded correspondence. Repeated letters, sending contexts, dedicated staff, and secret records turned individual skill into an institution that could compare and accumulate attacks. The deciphering book Soro mentioned in a 1511 petition is lost, so its contents cannot be reconstructed or made the sole origin of European cryptanalysis.
- Pause and ask
- What turns the lucky solving of one ciphertext into an organization that can work repeatedly on daily diplomatic mail?
- How thinking changed
- Preserving ciphertexts and known contexts from many senders lets dedicated secretaries compare new traffic with previous solutions. Cryptanalysis moved from private skill into a state function of document classification, workflow, and controlled access.
- What we cannot claim
- The 1511 anchor rests on Soro’s petition for reward based on his cryptanalytic work and book. The lost book’s contents cannot be reconstructed, and Venice is not made the sole birthplace of European cryptanalysis.
- This place
- As a Mediterranean node of trade and diplomacy, Venice received abundant cipher mail from distant embassies. The secret administration of the Council of Ten had continuing demand and authority to employ cryptanalysts such as Giovanni Soro and accumulate restricted records. (Venetian lagoon · islands · broadleaf trees · 45.4°N 12.3°E · landmark: St Mark’s Basilica (1094))
- Figure board
- A new letter is compared against an archive of earlier ciphertexts and solved cases, finding the same recurring group (63 18).
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
04·1586 CE·Paris(basis: Publication)
Letting the Plaintext Continue the Key — Vigenère’s Autokey
Vigenère’s Traicté des chiffres, printed in Paris, described an autokey that follows an initial secret with the plaintext itself so the choice of cipher alphabet does not simply repeat on a short cycle. It delayed the patterns an attacker sought while creating new problems of starting-key management and error propagation. The repeating-key table commonly called the “Vigenère cipher” owes much to earlier authors including Bellaso and is not Vigenère’s lone invention.
- Pause and ask
- If a short key repeats even across many alphabets, how might the repetition in the key itself be removed?
- How thinking changed
- Continuing an initial secret with plaintext removes a fixed repeating period. But sender and receiver must keep exactly the same position, and one error can propagate, so a stronger transformation creates new weaknesses of synchronization and operation.
- What we cannot claim
- Paris in 1586 marks publication. The entire repeating-key table now called the Vigenère cipher is not assigned to Vigenère alone; Bellaso’s 1553 method is distinguished from Vigenère’s autokey.
- This place
- Drawing on royal diplomatic experience, Vigenère used Paris print and book markets to publish a large treatise combining examples of secret writing from several cultures with his own methods. Print widened reproducible tables while later naming could obscure predecessors such as Bellaso. (Seine banks · broadleaf trees · flat basin · 48.9°N 2.4°E · landmark: Notre-Dame de Paris (1250))
- Figure board
- After one agreed starting key letter, the plaintext itself continues the key row, so no key repeats at a fixed interval.
- On the river
- A stack of books · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
05·1883 CE·Paris(basis: Publication)
The System May Be Known while the Key Must Endure — Kerckhoffs’s Principle
In an age of telegraphy and mass armies, Kerckhoffs argued that a military cipher should remain secure even if the system became known to the enemy, concentrating secrecy in a key that could be changed. Public scrutiny and manageable keys replaced concealment of the whole mechanism as a design ideal. The principle does not prove every compliant implementation secure, and nineteenth-century military requirements are not identical to every modern threat model.
- Pause and ask
- If the enemy learns the structure of the cipher machine, can security still be recovered by changing one small secret?
- How thinking changed
- Separating an algorithm that survives disclosure from a frequently replaceable key lets users recover from compromise without discarding every device. Security evaluation begins from an attacker knowing the system rather than trusting the inventor’s secrecy.
- What we cannot claim
- Kerckhoffs’s requirements are not a modern formal proof or a claim that open source alone is sufficient. Security includes a threat model, key generation, implementation, and operation, and nineteenth-century military context is kept distinct from today’s systems.
- This place
- Paris military-science journals and debates over telegraphy and mass armies made operational conditions public: many units would share a device and survive capture, betrayal, or leaked manuals. Kerckhoffs’s work in languages and military education joined design to use. (Seine banks · broadleaf trees · flat basin · 48.9°N 2.4°E · landmark: Notre-Dame de Paris (1250), Dôme des Invalides (1706))
- Figure board
- A cipher device E whose inner workings are fully visible takes only a small secret key K; if it leaks, just the key is swapped.
- On the river
- A stack of books · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
06·1918 CE·New York(basis: Patent)
Letter Ciphers Meet Electrical Signals — Vernam’s Patent
Gilbert Vernam filed a patent in 1918 for electrically combining the five-unit signals of telegraph characters with key signals read from paper tape and reversing the process at the receiver. Cryptography moved from hand-worked tables into bit operations, synchronized media, and the communication line itself. Vernam alone did not establish every one-time-pad condition—random non-repeating key, equal length, and single use—or its proof of security.
- Pause and ask
- Can key tape and an electrical circuit mix telegraph characters in real time instead of a person consulting a cipher table for every letter?
- How thinking changed
- Representing a character as five electrical units and reversibly combining it with key signals makes encryption and decryption the same machine operation. Secrecy shifts from an elaborate alphabet table to generating, copying, transporting, and synchronizing key tape.
- What we cannot claim
- The pin and year follow the patent’s 1918 Brooklyn filing, distinct from grant and publication in 1919. The patent alone did not complete every operating condition for random non-repeating keys or Shannon’s proof of perfect secrecy.
- This place
- AT&T and New York’s telegraph industry automated high-volume traffic and demanded a cipher device that did not slow the line. The Brooklyn filing address and corporate patent system turned an experimental circuit into legal drawings and a manufacturable arrangement. (Harbor and Hudson · broadleaf trees · low land · 40.7°N 74.0°W · landmark: Manhattan skyline (1913), Brooklyn Bridge (1883))
- Figure board
- Five-unit telegraph tape M is mixed hole by hole with key tape K by ⊕ to make C; mixing C with the same K gives M back.
- On the river
- A sealed box · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
07·1932 CE·Warsaw(basis: Main activity)
Writing Rotor Wiring as Permutations — Poland Breaks into Enigma
Marian Rejewski, working with Jerzy Różycki and Henryk Zygalski, modeled Enigma rotor wiring as permutations and combined mathematics with intelligence supplied through France and repeated German operating procedures to reconstruct the military machine and daily keys. Replica machines, cards, and sheets made search repeatable. A lone-genius story erases collaborators, intelligence, devices, and the changing wartime variants that were not all solved at once.
- Pause and ask
- If a machine changes keys daily and moves its rotors after every letter, can repeated operating procedures reveal its unseen wiring?
- How thinking changed
- Writing Enigma connections as permutations and cycles separates relationships leaked by repeated message keys from the machine’s physical wiring. Mathematics reduces possible structures, while intelligence, replicas, cards, and sheets turn the rest into executable search.
- What we cannot claim
- Warsaw in 1932 anchors the early reconstruction of military Enigma wiring. French intelligence, three mathematicians, and technical collaborators remain visible, and later naval and air-force variants and every wartime key were not solved at once.
- This place
- Facing German military pressure, Poland recruited German-speaking mathematicians from Poznań University into a Cipher Bureau course. Warsaw joined military traffic, intelligence supplied through France, mathematicians, and machine makers into a sustained team. (Vistula banks · broadleaf trees · flat plain · 52.2°N 21.0°E · landmark: Royal Castle, Warsaw (1619))
- Figure board
- Rotor wiring is written as a permutation of letters and split into cycles such as (A C F)(B E)(D H G) to read its structure.
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
08·1940 CE·Bletchley Park(basis: Main activity)
Finding Today’s Key before Today Ends — Intercepts, Cribs, and the Bombe
Bletchley Park connected Polish achievements, radio traffic from Y stations, probable plaintext cribs, Bombes designed through work by Turing, Gordon Welchman, and others, and the labour of thousands of operators and translators to reject rotor settings quickly. The timetable from interception through decryption to distribution mattered as much as one machine. Not every message was read, Turing did not break Enigma alone, and an exact number of years by which the war was shortened is a counterfactual rather than a settled fact.
- Pause and ask
- When there are too many keys to read one by one, can a small clue about likely plaintext let a machine reject wrong settings quickly?
- How thinking changed
- Turning a crib’s proposed plaintext–ciphertext relation into contradiction tests lets the Bombe reject impossible rotor settings in parallel rather than translate a whole message. Computation shifts from outputting the answer to shrinking the space humans must search.
- What we cannot claim
- The year 1940 anchors early British Bombe operation. Polish predecessors, Welchman and engineers, intercept staff, and operators remain visible; the scene does not claim every message was read, Turing acted alone, or a fixed number of war years was saved.
- This place
- Rail and communications access between London and many Y stations, a restricted estate, and mass recruitment let Bletchley Park assemble mathematicians, linguists, engineers, service members, and women operators in shifts. It was the center of a national interception and distribution network, not one mansion acting alone. (Fields · broadleaf trees · gentle lowland · 52.0°N 0.7°W)
- Figure board
- A probable plaintext (crib) is aligned with the ciphertext into letter pairs; settings that contradict them are struck out in bulk, leaving a few.
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
09·1949 CE·Bell Labs(basis: Main activity)
Asking How Much Secrecy Exists — Shannon’s Communication Theory
Claude Shannon modeled messages, keys, and ciphertexts as random variables and defined perfect secrecy as a ciphertext that adds no information about the message. Key space, redundancy, equivocation, and unicity separated “looking complicated” from security under a stated attack model. A classified 1945 report became a public paper in 1949, but the theory did not automatically solve implementation flaws, key distribution, human error, or every modern attack.
- Pause and ask
- Can “the attacker learns nothing more about the message from the ciphertext” be defined mathematically rather than by impression?
- How thinking changed
- Requiring P(M|C)=P(M), so message M and ciphertext C are independent, makes perfect secrecy a condition independent of an attacker’s computing power. Comparing language redundancy with key material also analyzes when other systems may expose a unique solution.
- What we cannot claim
- Perfect secrecy is a property of a stated model with sufficient key material and exact assumptions. Shannon’s paper did not solve key distribution, malware, side channels, authentication, or implementation errors or prove every modern cipher unconditionally secure.
- This place
- Bell Labs brought telephone and telegraph problems, wartime classified work, probability, electronics, and switching theory into one research environment. Information theory for noise and coding in long-distance communication gained a common language with attack models for secret systems. (Woods · broadleaf trees · low ridges · 40.7°N 74.4°W)
- Figure board
- The message probabilities before seeing ciphertext, P(M), and after, P(M|C), are identical bar for bar: the ciphertext adds no information.
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
10·1973 CE·Cheltenham(basis: Classified research)
Encryption without Sharing a Secret First — A Classified Discovery at GCHQ
James Ellis’s idea of “non-secret encryption” was made concrete by Clifford Cocks with an approach based on factorization and by Malcolm Williamson with a key-agreement method. Two distant parties could combine public information with their own secret calculations without a prior secure courier. The work remained classified until 1997, so it did not influence public research in the 1970s and was not identical in implementation or naming to later RSA and Diffie–Hellman.
- Pause and ask
- Can two people who have never met create a private computation using only public communication and no securely transported secret key?
- How thinking changed
- Publishing part of an encryption rule while each person keeps information needed for reversal changes the symmetric-key starting condition that both must already share one secret. Secure transport becomes a problem of computational difficulty and the structure of public and private information.
- What we cannot claim
- Cheltenham and 1973 mark internal GCHQ research, not public publication. Public researchers are not retroactively made readers of it, and the Cocks and Williamson methods are not treated as identical in every respect to later RSA and Diffie–Hellman.
- This place
- Managing government communications at scale, GCHQ in Cheltenham saw the bottleneck of securely distributing keys to every correspondent and let mathematicians and engineers inherit a long problem through classified documents. The same secrecy blocked outside scrutiny and influence. (Green vale · broadleaf trees · Cotswold hills · 51.9°N 2.1°W)
- Figure board
- With no secret shared first, only the public N travels; what reverses it, p · q, stays with the receiver. The work was classified until 1997.
- On the river
- A sealed box · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)
11·1976 CE·Stanford(basis: Composition)
Making a Shared Secret over a Public Channel — Diffie and Hellman
Whitfield Diffie and Martin Hellman published a key agreement in which exchanged public computations lead both parties to the same secret and framed public-key encryption and digital signatures as an open research program. A computation that is easy in one direction and difficult to reverse changed the role of the secure courier. Unauthenticated Diffie–Hellman does not prevent a man-in-the-middle attack, and Ralph Merkle’s preceding ideas and the then-classified GCHQ work remain part of the history.
- Pause and ask
- Over a public channel where an eavesdropper hears everything, can two people reach the same secret while making it hard for the listener to compute?
- How thinking changed
- Each party chooses a secret exponent and exchanges a public exponentiation, allowing both to compute the same combined value while an eavesdropper faces an inverse discrete-log problem. A key becomes a value created through interaction rather than a secure parcel, and digital signatures become a public research problem.
- What we cannot claim
- Basic Diffie–Hellman establishes a secret value but does not authenticate the other party and is vulnerable to a man-in-the-middle attack. Merkle’s contribution and independent GCHQ precedence remain visible, and one paper did not complete every practical protocol.
- This place
- Stanford’s electrical-engineering and computing environment and California debates over open networks moved key distribution into public journals rather than military or corporate secrecy. Seminars, preprints, and conferences made a common problem other researchers could attack and extend immediately. (Golden grass · oaks · rolling foothills · 37.4°N 122.2°W · landmark: Hoover Tower (1941))
- Figure board
- Each side picks a secret exponent a or b and sends only gᵃ or gᵇ over the open channel; both reach the same gᵃᵇ, which a listener finds hard to get.
- On the river
- A desk holding a written record · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)
12·1978 CE·Cambridge, MA(basis: Composition)
Easy to Multiply, Hard to Reverse — RSA Public Keys and Signatures
At MIT, Ronald Rivest, Adi Shamir, and Leonard Adleman used a composite made from two large primes and modular exponentiation to give a concrete method in which a public exponent encrypts or verifies while a secret exponent decrypts or signs. A key for everyone and a key held by its owner became distinct. Textbook “plain RSA” is not safe for direct modern use: padding, authentication, key generation, and the surrounding protocol all matter.
- Pause and ask
- Can one pair of computational keys let anyone lock a message for its owner and anyone verify a mark only the owner could make?
- How thinking changed
- The asymmetry between easily multiplying two large primes and hard factorization, together with modular inverses, creates public and private exponents. Encryption and signing become opposite directions in one algebraic structure, giving a concrete way to distribute keys through a public directory.
- What we cannot claim
- RSA security is not automatically proved by the sentence “factoring is hard”; key size, randomness, padding, implementation, and use matter. Deterministic plain RSA is not used directly in modern practice, and internet security is not reduced to one RSA invention.
- This place
- MIT’s computer-science community rapidly made the problem opened by Diffie–Hellman concrete through three researchers’ different intuitions and public review. Cambridge university, journal, and software cultures let the method be reproduced and attacked outside secret agencies. (Charles River · broadleaf trees · flat land · 42.4°N 71.1°W · landmark: MIT Great Dome (1916))
- Figure board
- Over n = p · q, the public exponent e locks or verifies and the secret exponent d unlocks or signs; the two directions undo each other.
- On the river
- A desk holding a written record · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)