Cracking SIGABA in less than 24 hours on a consumer PC
George Lasry · Cryptologia · 2021
The SIGABA was an electromechanical encryption device used by the US during WWII and in the 1950s. Also known as ECM Mark II, Converter M-134-C, CSP-889, and CSP-2900, the SIGABA was considered highly secure and was employed for strategic communications, such as between Churchill and Roosevelt. The SIGABA encrypts and decrypts with a set of five rotors and implements irregular stepping with two additional sets of five rotors. Its full keyspace, as used during WWII on some circuits, was in the order of 295.6. It is believed that the German codebreaking services were unable to make any inroads into the cryptanalysis of SIGABA. The most efficient modern attack on SIGABA published so far is a known-plaintext attack that requires at least 260.2 steps and extensive computing power. In this paper, the author presents a novel divide-and-conquer known-plaintext attack that can recover the key in less than 24 hours on a high-end consumer PC, taking advantage of multiple weaknesses in the design of SIGABA. With this attack, the author solved several series of full-keyspace challenges.