Spatial atlas

SPATIAL-COGNITIVE ATLAS · VOYAGE SEVEN

Cities That Kept and Broke Secrets — From Letter Frequencies to Public Keys

Cryptographic history is not a parade of geniuses inventing ever more complicated symbols. As letters, telegraphy, radio, and computer networks connected distant people, what an attacker could see, which keys had to be protected, and what counted as evidence of security changed together.

QUESTION FOR THE ROUTE

As communication became faster and wider, why did secrecy become less a matter of stranger-looking ciphertext and more a redesign of what could be public and which keys had to remain private?

WHAT THE LINE DOES NOT CLAIM

The line is neither proof that one cipher travelled unchanged from Baghdad to Cambridge nor a ranking of wartime victory or civilizations. It is the viewer’s edited itinerary across manuscripts, diplomatic mail, print, patents, telegraphy, radio interception, classified documents, and public journals that made different attacks and defenses visible; every pin states its own location basis and limit.

The camera rests on each city while you read, then eases through the runway between scenes. Select any marker or scene link to travel in either direction.

The same route, four questions

A lens never hides a scene or proves a cause. It changes which places you compare first, and the URL preserves your choice.

The whole-route view keeps problem, cognitive change, place, movement, and evidence boundary at equal weight. Choose a lens when you want to test a different explanation against the same scenes.

12 scroll-controlled map scenes

Live map · 지도를 불러오는 중…

11 / 12 · 1976 CE

Stanford

  1. 01 · c. 850 CE

    Baghdad · Composition

    Language Leaves a Fingerprint inside a Secret — Al-Kindi and Frequency Analysis

    A cryptanalytic treatise attributed to al-Kindi explains counting how often each letter appears in a long Arabic text and comparing that distribution with the most common symbols in a ciphertext to infer a monoalphabetic substitution. Replacing the same letter by the same sign hides words but preserves unequal repetition in language. The surviving manuscript is not an autograph, its exact room of composition cannot be fixed, and the work should not erase earlier secret-writing traditions as one solitary beginning of cryptography.

    PAUSE AND ASK

    If every letter has been replaced by another sign, can the ciphertext alone still reveal traces of its language?

    How the idea changed

    Replacing the same letter with the same sign hides word shapes but preserves unequal letter frequencies in the language. Comparing long plaintext and ciphertext distributions turned guessing at meaning into a measurable statistical attack.

    What this place made possible

    Court patronage, translation and copying, language study, and administrative and diplomatic texts in ninth-century Baghdad supplied readers and varied writing against which cryptanalysis could be described systematically. This is not collapsed into one modern-style institute called the House of Wisdom.

    How it moved

    Observation of Arabic letter use + traditions of secret writing in administration and diplomacy → frequency procedure in the treatise attributed to al-Kindi → preservation in later manuscripts → modern decipherment, editions, and histories of cryptology

    Do not overclaim

    The c. 850 Baghdad pin is an approximate activity and scholarly-context marker. The surviving manuscript is not an autograph and does not prove an exact room, exact year, or a solitary status as the first cryptanalyst.

    Evidence sources
    Stable link to this scene
    BaghdadRome
  2. 02 · c. 1466 CE

    Rome · Composition

    Rotating Away from One Fixed Alphabet — Alberti’s Cipher Disk

    Alberti described two rings of letters that could rotate into a cipher disk and a method for changing alphabets within a message. The idea unsettled the fixed correspondence that frequency analysis attacks. The treatise belongs to Alberti’s Roman activity around 1466–67 but was printed posthumously only in 1568; neither date nor one device completes every later polyalphabetic cipher.

    PAUSE AND ASK

    If frequency analysis looks for a fixed letter mapping, what happens when the mapping itself changes within the message?

    How the idea changed

    Rotating a disk changes the cipher alphabet so the same plaintext letter can receive different signs. An attacker must find switch points and several distributions, while defenders must agree not only on a key but on when to rotate.

    What this place made possible

    For Alberti as papal secretary and diplomat, Rome joined confidential correspondence among rulers and cities with a humanist culture of designing mechanical devices. A request from Leonardo Dati helped turn a practical problem into a treatise.

    How it moved

    Cipher correspondence of the papal court and city-states and Dati’s request → Alberti’s rotating disk and multiple-alphabet treatise → manuscript transmission → posthumous Venice printing in 1568 → later discussion of polyalphabetic ciphers

    Do not overclaim

    The treatise belongs to about 1466–67; 1568 is its posthumous publication. Rome marks an activity context, not the location of a surviving disk or exact study, and does not make Alberti the sole inventor of every polyalphabetic cipher.

    Evidence sources
    Stable link to this scene
    RomeVenice
  3. 03 · 1511 CE

    Venice · Main activity

    Cryptanalysis Becomes an Office and an Archive — Venice’s Diplomatic Ciphers

    The Venetian Republic joined the deciphering skill of secretaries such as Giovanni Soro to the work of the Council of Ten as ambassadors, merchants, and commanders generated coded correspondence. Repeated letters, sending contexts, dedicated staff, and secret records turned individual skill into an institution that could compare and accumulate attacks. The deciphering book Soro mentioned in a 1511 petition is lost, so its contents cannot be reconstructed or made the sole origin of European cryptanalysis.

    PAUSE AND ASK

    What turns the lucky solving of one ciphertext into an organization that can work repeatedly on daily diplomatic mail?

    How the idea changed

    Preserving ciphertexts and known contexts from many senders lets dedicated secretaries compare new traffic with previous solutions. Cryptanalysis moved from private skill into a state function of document classification, workflow, and controlled access.

    What this place made possible

    As a Mediterranean node of trade and diplomacy, Venice received abundant cipher mail from distant embassies. The secret administration of the Council of Ten had continuing demand and authority to employ cryptanalysts such as Giovanni Soro and accumulate restricted records.

    How it moved

    Cipher mail from overseas embassies → secret records of Venetian offices and the Council of Ten → repeated comparison and decipherment by Soro and colleagues → replies and diplomatic decisions → spread of specialist cryptographic offices to other Italian courts

    Do not overclaim

    The 1511 anchor rests on Soro’s petition for reward based on his cryptanalytic work and book. The lost book’s contents cannot be reconstructed, and Venice is not made the sole birthplace of European cryptanalysis.

    Evidence sources
    Stable link to this scene
    VeniceParis
  4. 04 · 1586 CE

    Paris · Publication

    Letting the Plaintext Continue the Key — Vigenère’s Autokey

    Vigenère’s Traicté des chiffres, printed in Paris, described an autokey that follows an initial secret with the plaintext itself so the choice of cipher alphabet does not simply repeat on a short cycle. It delayed the patterns an attacker sought while creating new problems of starting-key management and error propagation. The repeating-key table commonly called the “Vigenère cipher” owes much to earlier authors including Bellaso and is not Vigenère’s lone invention.

    PAUSE AND ASK

    If a short key repeats even across many alphabets, how might the repetition in the key itself be removed?

    How the idea changed

    Continuing an initial secret with plaintext removes a fixed repeating period. But sender and receiver must keep exactly the same position, and one error can propagate, so a stronger transformation creates new weaknesses of synchronization and operation.

    What this place made possible

    Drawing on royal diplomatic experience, Vigenère used Paris print and book markets to publish a large treatise combining examples of secret writing from several cultures with his own methods. Print widened reproducible tables while later naming could obscure predecessors such as Bellaso.

    How it moved

    Italian polyalphabetic ciphers and Bellaso’s repeating key + Vigenère’s diplomatic experience → 1586 Paris treatise including plaintext autokey → circulation in print → later reconstruction through tables, names, and military cipher manuals

    Do not overclaim

    Paris in 1586 marks publication. The entire repeating-key table now called the Vigenère cipher is not assigned to Vigenère alone; Bellaso’s 1553 method is distinguished from Vigenère’s autokey.

    Evidence sources
    Stable link to this scene
    ParisParis
  5. 05 · 1883 CE

    Paris · Publication

    The System May Be Known while the Key Must Endure — Kerckhoffs’s Principle

    In an age of telegraphy and mass armies, Kerckhoffs argued that a military cipher should remain secure even if the system became known to the enemy, concentrating secrecy in a key that could be changed. Public scrutiny and manageable keys replaced concealment of the whole mechanism as a design ideal. The principle does not prove every compliant implementation secure, and nineteenth-century military requirements are not identical to every modern threat model.

    PAUSE AND ASK

    If the enemy learns the structure of the cipher machine, can security still be recovered by changing one small secret?

    How the idea changed

    Separating an algorithm that survives disclosure from a frequently replaceable key lets users recover from compromise without discarding every device. Security evaluation begins from an attacker knowing the system rather than trusting the inventor’s secrecy.

    What this place made possible

    Paris military-science journals and debates over telegraphy and mass armies made operational conditions public: many units would share a device and survive capture, betrayal, or leaked manuals. Kerckhoffs’s work in languages and military education joined design to use.

    How it moved

    Operational problems of telegraphy and mass military communications → Kerckhoffs’s six requirements → 1883 serialization in the Paris Journal des sciences militaires → debate over military cipher design → modern reinterpretation as public algorithm and secret key

    Do not overclaim

    Kerckhoffs’s requirements are not a modern formal proof or a claim that open source alone is sufficient. Security includes a threat model, key generation, implementation, and operation, and nineteenth-century military context is kept distinct from today’s systems.

    Evidence sources
    Stable link to this scene
    ParisNew York
  6. 06 · 1918 CE

    New York · Patent

    Letter Ciphers Meet Electrical Signals — Vernam’s Patent

    Gilbert Vernam filed a patent in 1918 for electrically combining the five-unit signals of telegraph characters with key signals read from paper tape and reversing the process at the receiver. Cryptography moved from hand-worked tables into bit operations, synchronized media, and the communication line itself. Vernam alone did not establish every one-time-pad condition—random non-repeating key, equal length, and single use—or its proof of security.

    PAUSE AND ASK

    Can key tape and an electrical circuit mix telegraph characters in real time instead of a person consulting a cipher table for every letter?

    How the idea changed

    Representing a character as five electrical units and reversibly combining it with key signals makes encryption and decryption the same machine operation. Secrecy shifts from an elaborate alphabet table to generating, copying, transporting, and synchronizing key tape.

    What this place made possible

    AT&T and New York’s telegraph industry automated high-volume traffic and demanded a cipher device that did not slow the line. The Brooklyn filing address and corporate patent system turned an experimental circuit into legal drawings and a manufacturable arrangement.

    How it moved

    Five-unit telegraph codes in the Baudot family + AT&T line problems → Vernam’s key-tape combining circuit → Brooklyn filing in 1918 and US patent publication in 1919 → automatic military and diplomatic ciphers and one-time-tape development

    Do not overclaim

    The pin and year follow the patent’s 1918 Brooklyn filing, distinct from grant and publication in 1919. The patent alone did not complete every operating condition for random non-repeating keys or Shannon’s proof of perfect secrecy.

    Evidence sources
    Stable link to this scene
    New YorkWarsaw
  7. 07 · 1932 CE

    Warsaw · Main activity

    Writing Rotor Wiring as Permutations — Poland Breaks into Enigma

    Marian Rejewski, working with Jerzy Różycki and Henryk Zygalski, modeled Enigma rotor wiring as permutations and combined mathematics with intelligence supplied through France and repeated German operating procedures to reconstruct the military machine and daily keys. Replica machines, cards, and sheets made search repeatable. A lone-genius story erases collaborators, intelligence, devices, and the changing wartime variants that were not all solved at once.

    PAUSE AND ASK

    If a machine changes keys daily and moves its rotors after every letter, can repeated operating procedures reveal its unseen wiring?

    How the idea changed

    Writing Enigma connections as permutations and cycles separates relationships leaked by repeated message keys from the machine’s physical wiring. Mathematics reduces possible structures, while intelligence, replicas, cards, and sheets turn the rest into executable search.

    What this place made possible

    Facing German military pressure, Poland recruited German-speaking mathematicians from Poznań University into a Cipher Bureau course. Warsaw joined military traffic, intelligence supplied through France, mathematicians, and machine makers into a sustained team.

    How it moved

    German radio traffic and repeated message procedures + documents passed through French intelligence → permutation analysis by Rejewski, Różycki, and Zygalski → replica Enigma, cyclometer, sheets, and bomba → sharing methods and devices with Britain and France in 1939

    Do not overclaim

    Warsaw in 1932 anchors the early reconstruction of military Enigma wiring. French intelligence, three mathematicians, and technical collaborators remain visible, and later naval and air-force variants and every wartime key were not solved at once.

    Evidence sources
    Stable link to this scene
    WarsawBletchley Park
  8. 08 · 1940 CE

    Bletchley Park · Main activity

    Finding Today’s Key before Today Ends — Intercepts, Cribs, and the Bombe

    Bletchley Park connected Polish achievements, radio traffic from Y stations, probable plaintext cribs, Bombes designed through work by Turing, Gordon Welchman, and others, and the labour of thousands of operators and translators to reject rotor settings quickly. The timetable from interception through decryption to distribution mattered as much as one machine. Not every message was read, Turing did not break Enigma alone, and an exact number of years by which the war was shortened is a counterfactual rather than a settled fact.

    PAUSE AND ASK

    When there are too many keys to read one by one, can a small clue about likely plaintext let a machine reject wrong settings quickly?

    How the idea changed

    Turning a crib’s proposed plaintext–ciphertext relation into contradiction tests lets the Bombe reject impossible rotor settings in parallel rather than translate a whole message. Computation shifts from outputting the answer to shrinking the space humans must search.

    What this place made possible

    Rail and communications access between London and many Y stations, a restricted estate, and mass recruitment let Bletchley Park assemble mathematicians, linguists, engineers, service members, and women operators in shifts. It was the center of a national interception and distribution network, not one mansion acting alone.

    How it moved

    Radio interception at British and overseas Y stations → traffic analysis and crib construction → Turing and Welchman’s Bombe design building on Polish work → large-scale operation by Wrens → hut analysis and translation → restricted distribution of Ultra intelligence

    Do not overclaim

    The year 1940 anchors early British Bombe operation. Polish predecessors, Welchman and engineers, intercept staff, and operators remain visible; the scene does not claim every message was read, Turing acted alone, or a fixed number of war years was saved.

    Evidence sources
    Stable link to this scene
    Bletchley ParkBell Labs
  9. 09 · 1949 CE

    Bell Labs · Main activity

    Asking How Much Secrecy Exists — Shannon’s Communication Theory

    Claude Shannon modeled messages, keys, and ciphertexts as random variables and defined perfect secrecy as a ciphertext that adds no information about the message. Key space, redundancy, equivocation, and unicity separated “looking complicated” from security under a stated attack model. A classified 1945 report became a public paper in 1949, but the theory did not automatically solve implementation flaws, key distribution, human error, or every modern attack.

    PAUSE AND ASK

    Can “the attacker learns nothing more about the message from the ciphertext” be defined mathematically rather than by impression?

    How the idea changed

    Requiring P(M|C)=P(M), so message M and ciphertext C are independent, makes perfect secrecy a condition independent of an attacker’s computing power. Comparing language redundancy with key material also analyzes when other systems may expose a unique solution.

    What this place made possible

    Bell Labs brought telephone and telegraph problems, wartime classified work, probability, electronics, and switching theory into one research environment. Information theory for noise and coding in long-distance communication gained a common language with attack models for secret systems.

    How it moved

    Telegraph and telephone networks and wartime cryptographic research → Shannon’s classified 1945 memorandum → the entropy language of 1948 information theory → public 1949 Bell System Technical Journal paper → modern information-theoretic cryptography

    Do not overclaim

    Perfect secrecy is a property of a stated model with sufficient key material and exact assumptions. Shannon’s paper did not solve key distribution, malware, side channels, authentication, or implementation errors or prove every modern cipher unconditionally secure.

    Evidence sources
    Stable link to this scene
    Bell LabsCheltenham
  10. 10 · 1973 CE

    Cheltenham · Classified research

    Encryption without Sharing a Secret First — A Classified Discovery at GCHQ

    James Ellis’s idea of “non-secret encryption” was made concrete by Clifford Cocks with an approach based on factorization and by Malcolm Williamson with a key-agreement method. Two distant parties could combine public information with their own secret calculations without a prior secure courier. The work remained classified until 1997, so it did not influence public research in the 1970s and was not identical in implementation or naming to later RSA and Diffie–Hellman.

    PAUSE AND ASK

    Can two people who have never met create a private computation using only public communication and no securely transported secret key?

    How the idea changed

    Publishing part of an encryption rule while each person keeps information needed for reversal changes the symmetric-key starting condition that both must already share one secret. Secure transport becomes a problem of computational difficulty and the structure of public and private information.

    What this place made possible

    Managing government communications at scale, GCHQ in Cheltenham saw the bottleneck of securely distributing keys to every correspondent and let mathematicians and engineers inherit a long problem through classified documents. The same secrecy blocked outside scrutiny and influence.

    How it moved

    Key-distribution bottleneck in military and diplomatic communications → Ellis’s non-secret encryption idea → Cocks’s 1973 factorization method and Williamson’s key agreement → classified GCHQ documents → official disclosure in 1997 and reassessment of public-key history

    Do not overclaim

    Cheltenham and 1973 mark internal GCHQ research, not public publication. Public researchers are not retroactively made readers of it, and the Cocks and Williamson methods are not treated as identical in every respect to later RSA and Diffie–Hellman.

    Evidence sources
    Stable link to this scene
    CheltenhamStanford
  11. 11 · 1976 CE

    Stanford · Composition

    Making a Shared Secret over a Public Channel — Diffie and Hellman

    Whitfield Diffie and Martin Hellman published a key agreement in which exchanged public computations lead both parties to the same secret and framed public-key encryption and digital signatures as an open research program. A computation that is easy in one direction and difficult to reverse changed the role of the secure courier. Unauthenticated Diffie–Hellman does not prevent a man-in-the-middle attack, and Ralph Merkle’s preceding ideas and the then-classified GCHQ work remain part of the history.

    PAUSE AND ASK

    Over a public channel where an eavesdropper hears everything, can two people reach the same secret while making it hard for the listener to compute?

    How the idea changed

    Each party chooses a secret exponent and exchanges a public exponentiation, allowing both to compute the same combined value while an eavesdropper faces an inverse discrete-log problem. A key becomes a value created through interaction rather than a secure parcel, and digital signatures become a public research problem.

    What this place made possible

    Stanford’s electrical-engineering and computing environment and California debates over open networks moved key distribution into public journals rather than military or corporate secrecy. Seminars, preprints, and conferences made a common problem other researchers could attack and extend immediately.

    How it moved

    Merkle’s puzzles and public-key idea + Diffie’s authentication and signature problem + Hellman’s information-theory and mathematical work → Stanford collaboration → 1976 IEEE “New Directions in Cryptography” → worldwide public-key and protocol research

    Do not overclaim

    Basic Diffie–Hellman establishes a secret value but does not authenticate the other party and is vulnerable to a man-in-the-middle attack. Merkle’s contribution and independent GCHQ precedence remain visible, and one paper did not complete every practical protocol.

    Evidence sources
    Stable link to this scene
    StanfordCambridge, MA
  12. 12 · 1978 CE

    Cambridge, MA · Composition

    Easy to Multiply, Hard to Reverse — RSA Public Keys and Signatures

    At MIT, Ronald Rivest, Adi Shamir, and Leonard Adleman used a composite made from two large primes and modular exponentiation to give a concrete method in which a public exponent encrypts or verifies while a secret exponent decrypts or signs. A key for everyone and a key held by its owner became distinct. Textbook “plain RSA” is not safe for direct modern use: padding, authentication, key generation, and the surrounding protocol all matter.

    PAUSE AND ASK

    Can one pair of computational keys let anyone lock a message for its owner and anyone verify a mark only the owner could make?

    How the idea changed

    The asymmetry between easily multiplying two large primes and hard factorization, together with modular inverses, creates public and private exponents. Encryption and signing become opposite directions in one algebraic structure, giving a concrete way to distribute keys through a public directory.

    What this place made possible

    MIT’s computer-science community rapidly made the problem opened by Diffie–Hellman concrete through three researchers’ different intuitions and public review. Cambridge university, journal, and software cultures let the method be reproduced and attacked outside secret agencies.

    How it moved

    Diffie–Hellman’s public-key and signature agenda → MIT collaboration by Rivest, Shamir, and Adleman → combination of Euler/Fermat results with primes and factorization → 1977 report and 1978 CACM paper → standards, libraries, certificate ecosystems, and later attacks

    Do not overclaim

    RSA security is not automatically proved by the sentence “factoring is hard”; key size, randomness, padding, implementation, and use matter. Deterministic plain RSA is not used directly in modern practice, and internet security is not reduced to one RSA invention.

    Evidence sources
    Stable link to this scene

TOUCH THE MATHEMATICS

Cities That Kept and Broke Secrets — From Letter Frequencies to Public Keys

Twelve scenes connect letter frequencies in Baghdad, a rotating cipher disk in Rome, institutional diplomatic cryptanalysis in Venice, design principles in Paris, a telegraph device in New York, the Enigma networks of Warsaw and Bletchley Park, information theory at Bell Labs, classified work in Cheltenham, and public-key papers at Stanford and MIT. Cryptography changes from ever more elaborate letter substitution into layered problems of mathematics, machines, protocols, and key management.

Continue with the 96-second cinematic journey

OPEN THE FULL MAP

Follow the river of cryptography on the world map

Leave the edited twelve scenes and compare other people, problems, hubs, and routes in cryptography, information theory, and computation on the live map.

Explore the full map