55 70 ·8· 36 50 32 90 06 93 ·8· 73 ·1·1· 36 50 23 22 07 92 20
h  o      r  i  c  e  u  to     la        r  i  s  p  o  st a
… the opening of the despatch of 4 August 1629 under the 1628 key of Biermann and Bosbach; 1 and 8 are nulls

Vienna → Rome · homophonic cipher with nomenclator and nulls · August–November 1629

Pallotto to Barberini, 1629

Giovanni Battista Pallotta
fromGiovanni Battista Pallotta
Francesco Barberini
toFrancesco Barberini

Twenty-eight ciphered passages in the register of Monsignor Giovanni Battista Pallotto, archbishop of Thessalonica and nuncio to the Emperor: Vatican City, BAV, Barb.lat. 6960, digitised in full on DigiVatLib. DECODE carries them as R286–R313, all “Non-decrypted” (no decipherment on the record), and the catalogue entry said that what the cipher hides is not known.

The contents are known. Hans Kiewning printed these despatches in 1897 from the Roman office’s own decipherments, and the register’s clear pages confirm the identification word for word. The key is known too: Norbert Biermann and Thomas Bosbach recovered it in 2018 for the sibling volume Barb.lat. 6956, and George Lasry had found that 6960 uses it. Applied here to DECODE’s transcriptions, it gives running Italian in every record; about 1,750 three-digit code groups missing from the 6956 key stay open.

Daniel Bourdeau · posted · updated · key identified

Method: read with known key · Extent: complete

Update, 21 September 2026. George Lasry wrote: “Barberiniani Latini 6960 uses the same key as Barberiniani Latini 6956 (which was found by Norbert Biermann and Thomas Bosbach). I found this years ago, but the DECODE DB was never updated.” That key deciphers these ciphertexts, as section 00 shows. The analysis below records attacks made before the key was known; they failed. Its measurements stand. Its one positive finding was half right: the cipher does use fixed groups of varying length, but the analysis concluded from them that the cipher could not be homophonic, and the letters are homophonic. Its conclusion that the key was not known is superseded.
Summary (20 September 2026). Barb.lat. 6960 is the Barberini register of Pallotto’s nunciature at the imperial court in the second half of 1629, the months when the Mantuan succession was pushing the Emperor and France towards war. Its 194 pages interleave sheets written entirely in figures with pages of clear Italian. DECODE catalogued twenty-eight of the ciphered sheets with no decipherment and no indication of their contents. Their contents have been published since 1897: Hans Kiewning’s volume of the Nuntiaturberichte aus Deutschland for 1629 prints some forty of Pallotto’s despatches under the heading dechiffr., taken from the copies received and deciphered in Rome, now ASV, Nunz. di Germania 119. The first ciphered sheet, pp. 5–6, is headed in clear Di Vienna 4 di Agosto and is Kiewning’s Nr. 153; the register’s clear pages on either side of it run straight through the cipher sheet and carry that document’s wording exactly, and p. 13 is its second enclosure, again verbatim. So the contents were known; the key, on 20 September, was not. The cipher is numeric and written without separation, and its code width could not be established: there is no phase preference for two-digit or three-digit codes anywhere in the 112,805 digits. The opening twenty-seven letters of the 4 August despatch do align as two-digit codes, and then the alignment breaks for good. A control shows that twenty-seven is below the chance baseline for this material, so that match is not evidence of anything. No partial key is claimed: a held-out test shows that the table learned from one part of the despatch predicts the rest no better than the same table with its letters shuffled (0.355 confirmations per letter against a control mean of 0.359), so the 55 per cent consistency an aligner reports is the aligner fitting the crib. What the failure does have is a measured cause. On synthetic ciphertext (the same plaintext under a random two-digit key) the identical pipeline recovers the whole key from a clean transcription, 87 codes of 100 at a 0.5 per cent digit error rate, and 7 of 100 at 1.7 per cent, because each inserted or dropped digit flips the code phase for everything after it. So the method works. A third test then went further: the longest provably consistent two-digit alignment between the cipher and the known plaintext is 39 letters, and controls that shuffle the plaintext or reverse the cipher give 36 to 39, while the synthetic cipher at the same noise gives 207. The real material sits exactly on its chance baseline. Transcription noise is therefore not a sufficient explanation. A fourth test then searched the whole printed volume (1,161,303 letters) for the plaintext of any window of four of the ciphertexts, at code widths two, three and four, by a method calibrated to find a planted encipherment in 16 windows out of 254 even at the real noise level, with no false positives. It found nothing. So these ciphertexts are not fixed-width substitutions of any text printed in the edition. One test came back positive: the digit stream holds thirty-nine repeated twenty-four-digit strings where chance gives none, which a carefully used homophonic cipher would not produce. This pointed to a nomenclator writing each word or syllable the same way every time, in groups of varying length. A late find: DECODE’s own transcriptions carry some 640 clear-text annotations, and in five records a decipherment written on the page itself. Most of these despatches are mixed letters, short ciphered clauses set in clear Italian, which is why a crib drawn from the printed edition could not match them. That is where the next attempt should start. Status on 20 September, superseded by the update above: contents already in print; key not recovered, no partial key claimed, and every fixed-width hypothesis ruled out by calibrated controls. Two possibilities remained: a variable-length nomenclator, or ciphered passages whose Italian is nowhere in print because the edition summarises them in German.

00 The key, found by others

The sibling volume, Barb.lat. 6956, holds seventy ciphered sheets of the same nunciature for May to August 1628 (DECODE R215–R285 and R318). Its key was recovered in March 2018 by Norbert Biermann and, independently, Thomas Bosbach. Their two keys, a merged key and a sample decryption are filed on DECODE as documents attached to the first ciphertext record, R215, not as a key record. That is why this project's metadata harvest never saw them. DECODE still lists all twenty-eight 6960 records as “Non-decrypted”.

The system:

Applied to DECODE’s transcriptions of all twenty-eight 6960 records, dividing the digit stream into one-, two- and three-digit units by dynamic programming, the key gives running Italian in every record. R286 opens ho riceuto la risposta datami in scritto, the first words of Kiewning’s Nr. 153. About 2,000 nomenclator groups resolve from the 6956 key. About 1,750 three-digit groups do not appear in it; they are presumably names and titles particular to 1629, and they stay open. Some 200 digits fit no code, which is consistent with slips in the volunteer transcription. The unedited output is in the repository (pallotto1629/key6956/decrypt_6960.txt).

The key also explains why every attack below failed. A null or a three-digit group shifts the phase of every two-digit code after it, so no fixed-width alignment can survive more than a few words. That is where the first-pass crib match stopped: the 8 after ho had been taken as the first digit of a two-digit code. The long repeated digit strings that section 04 reports are the nomenclator and syllable groups, written the same way every time.

01 The volume and the twenty-eight ciphertexts

Barb.lat. 6960 is on DigiVatLib at digi.vatlib.it/view/MSS_Barb.lat.6960, 194 pages, with an IIIF manifest. It is an old bitonal microfilm scan and the image service’s own info.json gives a maximum of 748 × 1088 pixels per page; anything larger the server returns is an upscale of that. At that size a figure is about ten pixels wide. DECODE, however, holds its own scans of the same leaves at 1491 × 2066 (four times the pixel area) behind its login. Anyone transcribing this manuscript should work from those, not from DigiVatLib’s.

DECODE’s records R286–R313 are the twenty-eight ciphered passages; R315 is the volume as a whole, described there as “mixed ciphertext and cleartext”. Each record’s note gives its page range in the same DigiVatLib pagination, so DECODE page n is canvas n. The ranges run from pp. 5–6 to pp. 192–193, and the volume’s own title describes the ciphers of Pallotto dal 4 agosto al 29 settembre 1629, though the records carry dates as late as 29 November.

The cipher sheets are written across the full width of the page in a dense unbroken stream of figures, about thirty lines to the page and some sixty-six figures to the line. The clear pages are written quite differently, in a narrow column on the right of the leaf with a wide margin. The two alternate through the volume.

The head of page 5 of Barb.lat. 6960: the clear heading Di Vienna 4 di Agosto and Ill.mo et R.mo Sig.r Card.le P.rone, a struck-out line of plaintext, and then four lines of unbroken figures
Barb.lat. 6960, p. 5: the first ciphered sheet, headed in clear Di Vienna 4 di Agosto · Ill.mo et R.mo Sig.r Card.le P.rone, with a struck-out opening line of plaintext above the figures. Image: © Biblioteca Apostolica Vaticana, Barb.lat. 6960 p. 5.

Transcriptions of all twenty-eight were made for DECODE by volunteers in 2019 and 2020 and are downloadable as DOC_R*.txt. They record the figures one digit at a time, so the manuscript’s (decorative and irregular) grouping is lost. Measured, they come to 112,805 digits; the shortest is R308 at 854, the longest R306 at 9,332, and R286, the one worked in detail here, has 3,573.

02 The contents, printed in 1897

The relevant edition is Hans Kiewning (ed.), Nuntiaturberichte aus Deutschland nebst ergänzenden Aktenstücken. Vierte Abteilung: 17. Jahrhundert, Band 2: Nuntiatur des Pallotto 1628–1630, 2: 1629 (Berlin 1897). It is on archive.org as item 4-2_20200807, in full text.

Kiewning works from the copies received in Rome, ASV, Nunz. di Germania 119, and heads each ciphered despatch dechiffr. with the date the Roman office deciphered it: Nr. 153 is “Pallotto an Barberini, 1629 August 4, dechiffr. 22. August”. What he prints is therefore the contemporary decipherment. He gives the substantive passages in Italian verbatim and summarises the rest in German regesta, so the coverage is close to complete.

Two checks tie the register to the edition.

The 4 August despatch. The cipher on pp. 5–6 is headed Di Vienna 4 di Agosto, which is Nr. 153. The clear pages around it are the register’s own fair copy of the despatch, written apart from the cipher, and they run straight through the cipher sheet: p. 4 ends … non haver facoltà di accettar altro partito, che’l proposto in and p. 7 resumes nome del suo Rè. That sentence is Kiewning’s Nr. 153 word for word.

The enclosure. Page 13 is the paper Kiewning prints as Nr. 153, Beilage II, Propositione P. Valeriano per Sabran (his source: Bibl. Barber. LXIX 60 fol. 122). The manuscript reads, and the edition prints:

… il quale aggiunse di più, che fatta la pace, quando S. S.tà, come padre comune, proponga una lega et unione di questi eserciti, affine di abbatter il Turco commune nemico del nome christiano, che S. M.tà mandaria plenipotentiarii in Italia, acciò N. S.re potesse concludere così gran negotio, con che il demonio resteria ingannato e burlato.

Page 13 of Barb.lat. 6960, clear Italian in a narrow column: the proposal that the Pope, as common father, propose a league to strike the Turk, and that the Emperor send plenipotentiaries to Italy, with the devil left cheated and mocked
Barb.lat. 6960, p. 13: the enclosure to the despatch of 4 August 1629, printed by Kiewning as Nr. 153 Beilage II: P. Valeriano Magno’s proposal for Sabran, ending con che il demonio resteria ingannato e burlato. Image: © Biblioteca Apostolica Vaticana, Barb.lat. 6960 p. 13.

What the ciphers hide, then, is the business of the Mantuan succession crisis in the second half of 1629: Pallotto’s attempts, working through the Capuchin P. Valeriano Magno and the imperial minister Eggenberg (Echembergh in the despatches), to mediate between the Emperor and the French envoy Sabran over Casale and Monferrato, the civil rather than armed possession of the duchies, the withdrawal of the French from Susa and the imperial troops from the Grisons, and, behind it, the fear that the real object was to humble Venice and restore imperial authority in Italy.

03 The attacks made before the key was known

The figures are numeric only, written without separators. Across all twenty-eight ciphertexts the digit frequencies are uneven (0 at 16.1 per cent, 4 at 4.8 per cent), and adjacent digits carry about 0.18 bits of mutual information, so the stream is structured. The attacks below did not find the structure.

The code width does not show. For a fixed-width numeric code one phase should stand out from the others. None does. Taking the twenty-eight ciphertexts together, the index of coincidence of two-digit codes is 0.01462 at phase 0 and 0.01466 at phase 1, and the digit distributions at even and odd positions agree to within 0.2 per cent at every digit. Three-digit codes behave the same way at all three phases.

A crib aligns for twenty-seven letters, then fails. With the plaintext of Nr. 153 in hand, the opening of R286 aligns exactly, as two-digit codes, for twenty-seven letters:

55 70 83 65 03 29 00 69 38 73 11 36 50 23 22 07 92 20 86 72 52 06 38 97 12 33 23
H  O  R  I  C  E  V  U  T  A  L  A  R  I  S  P  O  S  T  A  D  A  T  A  M  I  I

The assignments repeat: 38 occurs twice and is T both times, 23 occurs twice and is I both times, which by chance would happen about once in 180 tries. The twenty-eighth code conflicts, and from there nothing is consistent. A banded dynamic-programming aligner over the whole despatch, allowing two-digit codes plus one- and three-digit resynchronisation for transcription slips, and iterating the code table to convergence against a hand-corrected 3,359-letter crib, reached about 55 per cent code-to-letter consistency, above the 20 per cent a wrong alignment gives and below what a recovered key gives.

Ciphertext-only search fails. Fixed-multiset simulated annealing over the hundred two-digit codes, on 5,000 codes of text, scored by a space-free Italian five-gram model built for this from the repository’s clean Italian corpora (12.0 million characters), settles at −3.54 log-probability per character where real Italian of the period scores about −1.5. A syllabic model of the same codes (each two-digit group standing for one to four letters) was tested against the known plaintext and collapsed back to single letters for every well-attested code, so no syllable table was found.

The 55 per cent is not a partial key. A held-out test shows this. Learn the table on the first 55 per cent of R286 against the crib, freeze it, then align the remaining digits to the remaining crib and count confirmations (cases where the code was already in the table and agrees). Against eight controls that keep the table but shuffle the letters among the codes:

confirmations per letterDP score
key learned from the first half0.355−3266
shuffled controls (mean of eight)0.359−3313

No separation. The same test on a “two-digit codes plus nulls, no digit slips” model gives 0.440 against a control mean of 0.431, again no separation. The consistency figure is the aligner fitting the crib, and any partial key read off it would have been an artefact.

The positive control. Encipher the same crib with a random two-digit homophonic key, damage the digit stream with single-digit insertions and deletions at a chosen rate, and run the identical learner. The fraction of the true key it recovers:

digit error ratekey recovered
0 %100 / 100
0.5 %87 / 100
1.7 %7 / 100
4 %19 / 100

The method works on synthetic text; it needs a transcription accurate to better than about half a per cent of digits. Above roughly one per cent a two-digit key cannot be recovered from this much text even with the plaintext in hand, because every inserted or dropped digit flips the code phase for everything after it. That also explains why no phase preference shows in the statistics above: slips scattered through thirty lines randomise the phase across the corpus.

The run-length test. A crib aligner can fake a fit, because a fresh code may always be given a fresh letter. What cannot be faked is a long consistent run: inside one window a repeated code must carry the same letter and the mapping must stay a function, so a false run dies at its first repeat conflict. Scanning every pairing of digit offset against crib offset and extending each run while it stays consistent:

longest consistent run
real cipher against the plaintext of Nr. 15339 letters
control: plaintext letters shuffled (five runs)39, 39, 36, 38, 36
control: cipher reversed39
synthetic two-digit cipher, same text, 1.7 % digit noise207 letters
synthetic two-digit cipher, clean transcription2705 letters

The real material sits on its own chance baseline, while a two-digit cipher at the same transcription noise runs five times further. The tool works: on that noisy synthetic text this method recovers 81 of 100 key codes, where the dynamic-programming learner managed 7. And because chance runs here reach 36 to 39 letters, the twenty-seven-letter opening match quoted at the top of this page is below the baseline. It is not evidence, and the one-in-180 figure given for it above is wrong.

So transcription noise is no longer a sufficient explanation. On this evidence the cipher sheet is not a fixed-width two-digit encipherment of the text Kiewning prints as Nr. 153. The next test widened that to the whole volume.

The corpus search. The run-length test compares one ciphertext with one crib. This compares four ciphertexts with the entire edition at once, exactly. For a substitution, equal codes force equal letters, so take a window of the cipher, list every pair of positions inside it holding the same code, and require the plaintext to repeat at precisely those offsets. That condition is checked across all 1,161,303 letters of Kiewning in one pass, with a bitmask per gap.

Calibrated by planting the true plaintext in the corpus and enciphering it with a random key:

windows hitting the true positionfalse positives
synthetic, clean transcription253 / 2540
synthetic, 1.7 % digit noise16 / 2540

So even at the real noise level about six per cent of windows still give an exact hit, and the method never fires falsely. Applied to four of the ciphertexts at three code widths:

recordwidth 2width 3width 4
R2860 / 2661 / 2610 / 256
R2920 / 4600 / 4560 / 452
R3060 / 7102 / 7050 / 700
R3110 / 5101 / 5050 / 500

The four apparent width-three hits are artefacts: every one lands in the edition’s index of Roman numerals (XIUXXUXXUIXXUIIXXUIII…), a degenerate stretch of corpus where any repeat pattern matches. There are no genuine hits. Under the hypothesis, R286 alone should have produced of the order of eight, so the probability of seeing none is around e−8.

What was left. The ciphertexts are not fixed-width substitutions of anything printed in the volume, of Nr. 153 or of any other despatch. Two possibilities remained. Either the system has variable-length groups, which no fixed-width alignment can match however good the transcription (the absence of phase preference points the same way), or the sheets encipher text that is not in the edition: Kiewning prints the substance in Italian but renders the rest as German regesta, and that Italian exists nowhere in print. The key (section 00) later confirmed the first. Both were testable, the first with a variable-length version of the same tool, the second by weighing a ciphertext’s length against the part of its despatch the edition only summarises.

How good is the transcription? Checked on DECODE’s larger scan, line 1 of p. 5 differs from DECODE’s transcription in two digits out of seventy-four, both substitutions, with no length difference (the transcription has 93 where the scan shows 73, and 30 where it shows 38). Line 2 differs by a digit or two and possibly in length. So the transcription is close, no length error is demonstrated at the point where the alignment breaks, and the break there is not a transcription artefact. Two explanations therefore remain open and cannot be separated from this material: the transcription carries enough length errors elsewhere to defeat recovery, or the cipher is not a fixed-width substitution of this plaintext at all.

04 What the cipher is

Every test above is negative. This one is not, and it constrains the system. Count repeated digit substrings across all twenty-eight ciphertexts (112,805 digits) against an independent control with the same digit frequencies:

substring lengthrepeats in the cipherindependent controlratio
4105,170102,8651.0×
664,0839,5906.7×
828,51991313×
1012,109112,000×
169660—
24390—

Thirty-nine repeated twenty-four-digit strings where chance gives none. A homophonic cipher used with care would not do that, since homophones exist to break repetition, and this hand repeats long runs constantly. What repeats like this is a code: a nomenclator in which a given word or syllable is written the same way every time. The key (section 00) has both: homophones for the letters, and fixed groups for syllables, words and names. The fixed groups of varying length explain why every fixed-width attack above failed. Segmenting the corpus by BPE gives 266 token types over 44,816 tokens, averaging 2.5 digits and spread over lengths one to seven: syllable-scale, and not a fixed width.

Two further hypotheses were tested and fail. The repeat spectrum of the first despatch matches its crib’s at roughly one digit per letter (3,570 digits against 3,359 letters), which for twenty-one letters over ten digits would mean a polyphonic cipher; there the constraint reverses, equal letters forcing equal digits. Longest consistent letter-to-digit run: 17 letters, against shuffled controls of 18, 19 and 18, which is chance level. And since encipherment preserves order, a repeated BPE token should land on the same plaintext word each time; 16 token types of 74 do, against controls of 13, 12 and 13. Not significant.

One correction. Section 03 above reports no phase preference at widths two and three. I first offered that as evidence against fixed-width codes, and that was too strong: at the observed digit error rate a single despatch carries some sixty slips, each flipping the phase for the rest of its line, which would wash out a real phase signal by itself. The phase test is inconclusive. The calibrated corpus search is the sound version of the claim, and it stands.

05 The annotations in DECODE’s transcriptions

DECODE’s transcriptions are annotated, and I had only skimmed the head of the first one. Across the twenty-eight files there are about 640 <CLEARTEXT> marks, and in five records <PLAINTEXT> lines, DECODE’s notation for a decipherment written on the document itself.

recordclear-text marksdecipherment on the page
R29868
R29663
R30554In un lungo discorso
R30753
R29251
R30935Con l’ord(ina)rio passato intendo che fu scritto da S. M.tà à…
R30822restati più contenti della risolutione
R31314Nel particolare

Most of these despatches are mixed letters: short ciphered runs set inside clear Italian, clause by clause. R308 has, on the leaf:

Non sono · 369092022550852359029255082700852173166 2 8 · circa il particolare de · 6680650…
with, written above the figures: restati più contenti della risolutione

That is an exact crib with known boundaries, in the right register, and it is nowhere in Kiewning. It also explains why a crib from the printed edition could not match a record like this one: the ciphered passage is a single clause, and the edition prints the sense of the whole letter.

This crib did not fit either. Forty-one digits for thirty-four letters, with the figures and the gloss both checked against DECODE’s 1523 × 2088 scan. Searched exhaustively, under the deterministic constraint that section 04 implies and again allowing homophones:

modelresult
fixed width 1, 2 or 3no fit (41 is not divisible by 2)
deterministic letter code, groups of 1–2 digits0 solutions (exact)
deterministic letter code, groups of 1–3 digits0 solutions (exact)
2-digit groups, syllables of 1–3 letters0 solutions (exhaustive, 4.0 M nodes)
the same, homophones allowed0 solutions (exhaustive, 7.3 M nodes)

So either the decipherer’s gloss does not align exactly to that run (he may have glossed only part of it, or run on into the next), or the system is more complex than any of these. That is where the work stood on 20 September.

06 What stays open

07 Sources

Working files, the DECODE transcriptions, the crib, the aligners and the solver: pallotto1629/.