Doppelkastenschlüssel — German Double Playfair
Two rows, vertical pairs, and two successive substitutions
Allied crib and digraph-statistical attacks are documented for German double-box field ciphers; variants must be distinguished.
December 1941 procedure only. Uppercase A–Z; accents stripped; J becomes II; nonletters discarded. Odd plaintext gets the selected filler (default Z, not X). Ciphertext must omit J and have complete pairs; transmitted body maximum 500 letters.
Step, Play/Pause and Reset keep keyboard focus on the control. With reduced motion enabled, Play shows the completed arrangement immediately.
Why This Matters
Pair formation is part of the cipher, not mere presentation. Following a complete original example makes conventions observable: a changed boundary, pairing rule or final cell changes the ciphertext.
This page reconstructs one edition: Vorläufige Schlüsselanleitung zum Doppelkastenschlüssel, Ausgabe Dezember 1941. The German armed forces used a two-box digraph cipher in WWII; its arrangement and repeated substitution distinguish it from the generic Two-Square exhibit.
Related procedures changed over time. The 1940 instructions, the later Truppenschlüssel and Nachrichtenschlüssel are not interchangeable names for this implementation. In particular, the Truppenschlüssel’s single-stage substitution must not be substituted for this edition’s two stages. RS44 began replacing Double Playfair during 1944.
- Prepare letters; J is represented by II (two letters), as §4 requires. If the length is odd, append an operator-selected letter other than X. This demo chooses Z by default and never removes it automatically.
- Write each full 34-letter block as two rows of 17. Divide a final shorter, even block equally between two shorter rows; do not pad it to 17 columns.
- Form pairs vertically: top-row letter first, bottom-row letter second. Locate the first in square A and the second in square B.
- If the positions share a row, replace each by its right neighbour, wrapping at the edge, and output the B replacement first. Otherwise take the rectangle corners: first output from B at A’s row and B’s column, second from A at B’s row and A’s column.
- Apply that same rule again to the intermediate pair, still locating its first letter in A and its second in B. The second result is ciphertext.
For decryption, locate the ciphertext pair’s first letter in B and second in A. Apply the inverse rule twice: same-row moves are leftward, and rectangle corners cross back. Rebuild the two plaintext rows and read the top row before the bottom. Adjacent repeated letters are not split by a Playfair-style X.
The squares and 54-letter message come from printed pp. 4–6, §§9–23. Two short examples pin both branches: AA → VR → FY and FA → TR → VD. The full message uses a 34-letter block followed by a 20-letter block.
Square A: HILQETUARSBKXFGPWCOZDVYMN Square B: ZNOCHBXAVIUDTGWMYELSKPQRF Prepared plaintext: FEINDLIQERANGRIFFAUFSTRASZEADORFSTRIQBEHAUSENABGEWEHRT Ciphertext body: VDLGCTUQZREOMFCIFEALFYLBAPKWCTEIWBTYMFLNMVMQZTVLHUPILF
The engine is checked against these printed answers in both directions. No output from this engine was used to invent the expected values.
Ostwald and Weierud describe Allied work on Double Playfair by John Tiltman’s British team and U.S. cryptanalysts, including Joseph S. Schick’s account of the 849th Signal Intelligence Service, using known or probable plaintext and digraph statistics. The cipher’s plaintext arrangement changes which letters are paired; it does not remove statistical structure.
Their modern hill-climbing results concern the related Truppenschlüssel. Those results must not be described as a test of this December 1941 two-stage engine. The daily key consists of two ordered 25-letter squares; a nominal settings count does not establish resistance to crib-based cryptanalysis.
The demo models this edition’s pairing, same-row rule, two substitution stages and inverse reconstruction. The museum applies accent stripping and discards punctuation and digits. German field-message abbreviations, umlaut expansion, spelled-out numbers, operational headers, identification groups, daily-key distribution and emergency square construction are left to the operator and are not simulated.
The real operator chose an odd-length filler from the allowed letters. A selectable, repeatable filler makes testing understandable; it is not an undocumented escape protocol. A genuine trailing Z remains indistinguishable from a filler Z. The UI enforces the 500-letter transmitted-body limit. The pure engine can process longer blocks for complexity testing when that operational check is explicitly disabled.
| Exhibit | 166 of 167 |
| Origin | German armed forces |
| Family | Two-stage digraph substitution |
| Key | Two ordered 5 × 5 squares; 17-column pairing |
Original December 1941 manual: printed pp. 3–6, §§4, 9–23; NARA RG 457, Box 7, Nr. 57; facsimile curated by Frode Weierud at CryptoCellar.
Olaf Ostwald and Frode Weierud, Modern Cryptanalysis of the Truppenschlüssel (2021 author manuscript; published in Cryptologia 47(3), 2023, pp. 261–281): historical comparison and procedure distinctions. Its attack results target Truppenschlüssel.
Square diagrams are rendered from factual key letters; no source scans or third-party images are reproduced.