01 The object
A sheet received by the Secret Service on 24 April 1935, according to the receiving stamp on its face, headed “Secret Service” in a looping hand, with a diagonal “261” top right, three lines of digits, two lines of block capitals, and a skull and crossbones above a dagger driven through a boot. William Friedman reproduced it as figure 2 of the first of his 1959 lectures, printed by the NSA as The Friedman Legacy (1992), with one sentence: an authentic example of a transposition cipher, sent to President Roosevelt, which the Secret Service asked him to decipher, and which to his chagrin said “Did you ever bite a lemon?” That reading takes every second letter of NDOIMDEYLOAUEETVIEBR?; the line under it, OR ELSE YOU DIE!!, is in clear. Friedman said nothing about the digits.
Klaus Schmeh posted the letter in 2015 and again in December 2017 as number 17 of his fifty unsolved cryptograms. In the comments Marc Gutgesell observed that no tick-joined pair repeats and that the loose digits are 1 to 9; Thomas Ernst listed the 43 pairs, found they were exactly 10 to 52, and concluded the block was “a doodle, if not a fake”, perhaps made to give Friedman a lemon to bite. Nobody has proposed a reading since.
02 The reading
Two copies exist: Schmeh’s 614-pixel scan and the figure in the NSA book. The Internet Archive holds a 300 ppi scan of the book, and its figure, cropped here, is the sharpest copy of the block that can be had without the original.
The “apostrophes” of the standard transcription are short ticks written between and above two digits, and the two digits under a tick are one number. Digits without a tick stand alone. Read that way the block is:
1 7 2 10 15 17 19 21 26 8 32 33 20 37 000000 16 27 12 34 38
28 22 39 40 41 42 48 44 000000 9 3 13 000 18 4 23 24 000
46 29 35 51 5 43 47 000 6 11 36 50 52 30 49 45 25 31 14 —
The 43 pairs are the numbers 10 to 52, each exactly once. The nine loose digits are 1 to 9, each exactly once, in the order 1 7 2 8 9 3 4 5 6. The eighteen zeros come in groups of 6, 6, 3 and 3. That is the whole content of the block: a permutation of 1 to 52 with four separators. Friedman’s or the Secret Service’s pencilled trial letters under the digits, which two commenters noticed, are not recoverable from either scan.
03 A shuffle written by hand
A permutation of 52 numbers can be tested against a fair shuffle. This one fails in four ways at once.
| statistic | observed | fair shuffle of 52 | p (200 000 shuffles) |
|---|---|---|---|
| rank correlation of value with position | +0.39 | 0 | 0.002 |
| neighbours differing by exactly +1 | 5 | about 1 | 0.003 |
| rising chains (values whose positions increase) | 16 | about 26.5 | below 1 in 200 000 |
| neighbours summing to 53 | 4 | about 1 | 0.018 |
The rising chains are the telling one. Follow each value to the next: 1 2 3 4 5 6 appear in that order along the block, so do 7 8 9, 21 to 25, 26 to 31, 32 to 36 and 37 to 43. The writer worked upward through the unused numbers in several interleaved passes, fell back for the ones skipped, and when fresh numbers ran short wrote 39 40 41 42 straight off. Every anomaly in the table is of that kind. Three of the four pairs summing to 53 straddle a zero group (37|16, 44|9, 47|6), which Gerd noticed in 2017; it is a mild excess and not a structure anything else depends on.
The one object that comes in 52 is a deck of cards, so the block was also tested as a riffle-shuffled deck. Sixteen rising chains is what four riffles produce, but a deck riffled four times does not also drift upward by 0.39 and run four consecutive cards: the joint event has probability 0.003 under the Gilbert-Shannon-Reeds model at four riffles and 0.023 at three. A hand-written list explains the block better than a deck does. Neither contains a text.
04 The cipher readings that can be tested
A block in which every number appears once can be a cipher in only two ways: a homophonic substitution with 52 homophones each used once, or a transposition key derived from a 52-letter phrase by ranking its letters. With an unordered key either reading can produce any 52-letter text at all, so neither can be tested or refuted; one commenter demonstrated this by fitting an arbitrary sentence. With an ordered key, homophones assigned to the alphabet in order or the phrase recovered from the inverse permutation with letters nondecreasing along the ranks, the plaintext is fixed by 51 boundary choices, about 66 bits, against roughly 70 bits of redundancy in 52 letters of English. That is testable, just.
The test: simulated annealing over nondecreasing maps from 1 to 52 onto the alphabet, scored by a character 5-gram English model, in six readings (sequence order and inverse permutation, alphabet forward and reversed, zero groups as word breaks or ignored), with 60 restarts of 60 000 steps each. The control: 52-letter passages of Dickens and Melville enciphered with ordered homophonic keys and attacked identically.
| reading | best score, nats per letter | best candidate |
|---|---|---|
| sequence, alphabet a to z | −3.02 | abadefillbookofmdoomloorstsbadfallsnowassadovyouslod |
| sequence, a to z, zeros as word breaks | −2.70 | abadefillbooko endoonloorsus dad falltoowast adovyouslod |
| sequence, alphabet z to a | −3.18 | uttooooonsnnolonominoffeedertootooenlatedtoldandenno |
| inverse permutation, a to z | −2.63 | derssteeretiryehereheissuehistwehisthinnootrustoutst |
| inverse permutation, z to a | −3.03 | ttheeetsiteseatstetstreeatssedassseesspooneibeendeed |
| controls, 8 passages | −1.48 to −1.97 | 7 of 8 read at 88 to 100% of letters; one at 46% |
Nothing from the block comes within 0.6 nats per letter of a recovered control, and no candidate holds a run of English longer than a chance word. The block’s own structure works against an ordered key: under a forward alphabet the nine single digits must all become a, b or c, so every candidate opens “aba”. The ordered readings are excluded at the strength the controls allow; the unordered ones cannot be tested, and a block that is only consistent with an untestable key is not distinguishable from a doodle.
05 What it means
Ernst’s arithmetic is right, and the permutation carries the fingerprints of a hand that wrote 1 to 52 once each in a made-up order, then dressed the list with runs of zeros. The letter lines below it are a transposition so shallow that Friedman read it at sight; the number lines above are a cipher-shaped object with nothing inside. Whether the sender meant it as a hoax on the Secret Service, as Ernst suggests, or simply copied out what he thought a cipher looked like, the block cannot be read because it does not encode anything. An unordered one-time key remains possible in principle and is indistinguishable from a doodle.
What would reopen the question: the original sheet in the William F. Friedman Collection at the NSA, whose reverse carries a typed text and whose face carries the pencilled trials, or a second message from the same hand.
06 Sources
- William F. Friedman, The Friedman Legacy: A Tribute to William and Elizebeth Friedman, NSA Center for Cryptologic History, Sources in Cryptologic History 3, 1992, lecture I, p. 8 and fig. 2. FDLP PDF; Internet Archive scan (leaf 18), source of the figure above.
- Klaus Schmeh, “Wer knackt die verschlüsselte Nachricht an Präsident Roosevelt?”, Cipherbrain, 26 October 2015, with Marc Gutgesell’s comments.
- Klaus Schmeh, “The Top 50 unsolved encrypted messages: 17. The Roosevelt cryptogram”, 8 December 2017, with Thomas Ernst’s, Thomas’s, Gerd’s and Norbert’s comments.
- Reproduce with
roosevelt/structure.pyandroosevelt/solve_ordered.pyin the repository; the reading is inroosevelt/cipher.txt.