Hagelin C-36 / C-52 Lineage
Pins and lugs made portable encryption practical — and vendor trust became part of the key
The pin-and-lug family has published cryptanalytic attacks; Greenough’s 1999 C-52 attack uses known plaintext.
Why This Matters
Hagelin’s machines made encryption portable without making it electronic. Pins around wheels selected mechanical levers; lugs on a cage converted those binary signals into a changing alphabet shift. The C-series also illustrates a second question: who controls the design, sales, and operating instructions of the equipment you trust?
Boris Hagelin developed the C-series at AB Cryptoteknik in Sweden during the 1930s. The C-36 belongs to the early pin-and-lug family; the later C-38 became the US Army’s M-209. Around 1952 the C-52 and related CX-52 expanded the design in the era of Hagelin’s Swiss company, Crypto AG.
| Machine | Place in the family |
|---|---|
| C-36 | Early portable pin-and-lug design; configurations and lug arrangements varied. |
| C-38 / M-209 | Six pinwheels and a lug cage; the US military’s mass-produced tactical machine. |
| C-52 / CX-52 | Postwar successors with selectable wheels and additional configuration options; some variants used irregular stepping. |
Each wheel carries active and inactive pins. Their positions determine which guide arms engage the lugs attached to cage bars. As the operator turns the handle, displaced bars contribute to a numerical key value. A changing shift combines that value with the input letter.
For the reciprocal letter-subtractor convention, number A–Z as 0–25 and compute C = (K − P) mod 26. Applying the same K sequence to C recovers P. The difficult part is generating K, not the subtraction. A long wheel cycle alone does not guarantee that the resulting shifts lack exploitable structure.
Try the M-209 encrypt/decrypt demo for the museum’s pin-and-lug interactive. It illustrates a related machine, rather than pretending to reproduce every C-36 or C-52 configuration.
H. Paul Greenough published a known-plaintext attack in 1999 against the C-52 and similar machines with irregular pinwheel stepping. The attack determines the subset of wheels, their order, and active pin positions from the constraints imposed by matching plaintext and ciphertext. This is a public cryptanalytic result, distinct from a claim that every machine sold under the family name shared one weakness.
The M-209 exhibit covers wartime known-plaintext and statistical attacks on that earlier branch. Public attacks exist against members of the cipher family; those results are not a blanket statement about identical internals or attacks across all variants.
William Friedman’s declassified reports document US intelligence contact with Hagelin, discussions of C-52 variants, and attention to which customers received which machines. Later, Crypto AG was secretly owned by the CIA and West German BND from 1970 as part of the operation known as Rubicon. Selected export designs and procedures were influenced to make foreign traffic readable.
The company history must not be projected backwards onto every C-36. A wartime C-36, a publicly attacked C-52 configuration, and a deliberately weakened later export product are different claims. The lesson is that secret keys cannot repair a supplier’s deliberately constrained design or operating procedure.
Pin-and-lug machines turn a physical key into a stream of shifts, making key generation, key reuse, and biased output visible. Crypto AG adds the need for independent design review. A trusted brand, an impressive mechanical period, and a confidential sales process are not substitutes for public cryptanalysis.
| Exhibit | 162 of 167 |
| Designer | Boris Hagelin |
| Lineage | C-36 → C-38 / M-209 → C-52 / CX-52 |
| Family | Mechanical pin-and-lug stream cipher |
| C-52 era | Around 1952 |
| Published attack | H. Paul Greenough · 1999 · known plaintext |