721.7B+ configurations evaluated across recorded experiments

Odd and even in the K4 cribs

Colin Patrick noticed a small regularity in the two stretches of K4 plaintext that Jim Sanborn has released. It takes a few minutes to check by hand. We checked it by machine, wrote the arithmetic on this page as proofs that a computer verifies step by step, and worked out what the pattern would and would not mean if it is more than chance.

In plain English: number the letters A = 0 to Z = 25 and, at each crib position, add the cipher letter’s number to the position. Every plaintext letter that appears more than once in the cribs gives an answer that is odd every time or even every time: 13 pairs out of 13. With random cipher letters that happens about once in 2,000 tries. Allowing for the other patterns that were looked at before this one turned up, it is more like once in 100 to 200. If the pattern is real, it is a fact about the key, not the message. It cannot be used to find the plaintext: the cipher method that would explain it narrows each unknown letter by one odd-or-even test, and nothing more.

The pattern

The ciphertext is the standard 97-letter transcription. The cribs are EASTNORTHEAST at positions 22–34 and BERLINCLOCK at positions 64–74, counting from 1. At each crib position, take the cipher letter’s number (A = 0, B = 1, …, Z = 25) and add the position. In the table, the cipher letter is in brackets after its number.

LetterPosition + numberOdd or even
E22 + 5 (F) = 27
31 + 6 (G) = 37
65 + 24 (Y) = 89
all odd
S24 + 17 (R) = 41
33 + 18 (S) = 51
odd
O27 + 16 (Q) = 43
72 + 5 (F) = 77
odd
R28 + 15 (P) = 43
66 + 15 (P) = 81
odd
A23 + 11 (L) = 34
32 + 10 (K) = 42
even
T25 + 21 (V) = 46
29 + 17 (R) = 46
34 + 18 (S) = 52
all even
N26 + 16 (Q) = 42
69 + 19 (T) = 88
even
L67 + 21 (V) = 88
71 + 25 (Z) = 96
even
C70 + 12 (M) = 82
73 + 15 (P) = 88
even
H, B, I, KH: 30 + 13 (N) = 43
B: 64 + 13 (N) = 77
I: 68 + 19 (T) = 87
K: 74 + 10 (K) = 84
once each

That is 13 pairs of matching plaintext letters, and all 13 agree. They are not 13 separate tests: a letter seen three times gives two independent comparisons, so there are 11 independent checks. The letters fall into two groups: B, E, H, I, O, R, S on the odd side and A, C, K, L, N, T on the even side.

The usual conventions make no difference. Counting positions from 0, or numbering the alphabet from A = 1, flips every answer at once, so the pairs still agree.

A fair first objection is that the two EASTs are nine positions apart, so their positions already differ between odd and even. That is exactly why it is a test. For E to keep the same total, its cipher letter has to switch too, and it does (F = 5, then G = 6). All four letters of EAST do: FLRV are all odd (5, 11, 17, 21) and GKSS are all even (6, 10, 18, 18).

Why it is about the key

In the cipher families most often proposed for K4, each plaintext letter is shifted along the alphabet by a key letter. Vigenère, Beaufort and variant Beaufort differ only in the direction of the shift. In all three, whether the key plus the position is odd or even is fixed by two things: the same odd-or-even answer as in the table, and the plaintext letter. Within a pair the plaintext letter is the same, so it cancels. The pattern therefore says: at the crib positions, whether the key plus the position is odd or even depends only on which plaintext letter is being enciphered.

Going round the end of the alphabet does not disturb this, because 26 is even: taking away 26 never changes whether a number is odd or even.

One of the 13 pairs was already known. R at positions 28 and 66 is enciphered as P both times, so the key is the same at those two positions. That is the key equality Richard Bean recorded in his 2021 paper (he counts from 0, so it appears there as positions 27 and 65). Colin did not find the odd-and-even pattern across the other pairs stated there or elsewhere.

The algebra
key = C − P   (Vigenère)
key = C + P   (Beaufort)
key = P − C   (variant Beaufort)        all counted mod 26

parity(key + i) = parity(C + i) + parity(P)       in every case, mod 2

same plaintext letter P at positions i and j:
  parity(Ci + i) = parity(Cj + j)   exactly when   parity(keyi + i) = parity(keyj + j)

Parity is well defined on letters counted mod 26 because 26 is even, so reducing mod 2 is compatible with every addition and subtraction above.

How unusual it is

“How likely is this by chance?” has more than one honest answer, depending on what is allowed to be random. All three below are exact counts, not estimates.

Then there is how the pattern was found. Colin came across it while computing about ten different statistics on the cribs, and also tried the KRYPTOS-keyed alphabet, where the pattern does not appear (6 of 13 pairs agree). His own allowance for that search puts a fair overall figure at roughly 1 in 100 to 200. That allowance is a judgement, not a calculation, and it is the honest headline: interesting, not proof.

What it says about how K4 was built

Suppose K4 combines a letter-for-letter substitution (a mixed alphabet) with a shifting key. If the pattern comes from the method rather than luck, it means the pattern would hold whatever key had been chosen. Under that assumption, which the proofs state openly, the order of the two steps matters:

It also says less about the cipher alphabet than it might seem to. The pattern only fixes which letters count as odd and which as even. Any renumbering that keeps the odd letters together, or swaps the two halves wholesale, keeps all 13 pairs; swapping A and C is one example. So the pattern points to an alphabet whose odd/even split is the ordinary one, not to the ordinary order itself.

Together with the Stehle run

K4 has a second well-known oddity next to BERLINCLOCK. In the nine letters DIAWINFBN at positions 56–64, every letter is exactly five places further along the alphabet than the letter four positions before it (D to I, I to N, A to F, W to B going round from Z to A, I to N). Ferdinando Stehle pointed this out on the sci.crypt newsgroup in 2000, and Bean’s 2021 paper cites it. Allowing for the fact that both the gap of four and the place were found by looking, a run like this turns up by chance about once in 205 tries.

If both patterns are real and come from the “substitute first, then shift” method above, they combine like this:

What it cannot tell us

This is the most important result on the page. Under that method, once the substitution is fixed, a candidate plaintext is possible for some key exactly when it passes one odd-or-even test at each position. The key is otherwise free, so the method never predicts a key value. The Stehle run adds nothing beyond that test: any plaintext that passes it already has all the Stehle consequences above.

The test allows exactly 13 of the 26 letters at each unknown position once the substitution is known, and more before it is. That still leaves 13 choices for each of the 73 unknown letters before anyone asks whether the result reads as English. To show how loose it is, the proofs include a complete 97-letter plaintext that fits both patterns and both cribs and uses only A and B everywhere else. Guessing plaintext against these constraints is not a way to search. Their use is to reject proposed solutions that come from somewhere else.

What new plaintext would show

If the pattern comes from the method, it has to hold across the whole message: every plaintext letter must give the same odd-or-even answer at every one of its positions. Over 97 letters that is dozens of independent checks, which chance would essentially never pass. If more plaintext is ever published, this is a one-line check.

Any newly released crib letter that is one of the 13 grouped letters must land in its group, and each one is a fair test with an even chance of breaking the pattern. If the pattern is luck, eight such letters would all fit only about once in 256 tries.

Checked by computer

The arithmetic on this page is written as proofs in Lean, a proof assistant: a program that checks every step of a mathematical argument and refuses any step it cannot verify. The proofs start from the carved ciphertext itself, read letter by letter, and an automated test fails if that text ever differs from the repository’s reference copy. A final audit confirms that no step was taken on trust.

Four figures are exact counts made by a short Python script in the same folder rather than Lean proofs: the shuffle and random-numbering odds, the KRYPTOS-alphabet count and the transposition count. The 1-in-205 figure for the Stehle run comes from a separate script, linked below.

Reproduce

bash formal/k4_parity/reproduce.sh

Run from a clone of the kryptos repo. Needs Python 3.11+ and elan, the Lean installer. The first run downloads the Lean toolchain, the Mathlib library and its prebuilt files; allow about 11 GB of disk space. The proofs, the script and a theorem-by-theorem index are in formal/k4_parity.

What changed when the arithmetic was checked

Writing the proofs changed four things in the original write-up of this pattern.

  1. It had said the pattern pins the cipher alphabet to the ordinary order, up to a simple multiply-and-shift relabeling. It pins only the odd/even split. Every one of the roughly 7.8 × 1019 numberings with the ordinary odd/even split keeps all 13 pairs, and only 312 of those are multiply-and-shift relabelings; swapping A and C is one that is not.
  2. The random-numbering odds are 1 in 433, not 1 in 2,048, because two of the checks pass under every numbering. An earlier sampled estimate of 1 in 457 is replaced by the exact figure, and the sampled shuffle figure of 1 in 2,012 by the exact 1 in 1,996.
  3. “No plaintext letter repeats four positions later” does not need the substitution to be one-to-one. Any substitution will do.
  4. The order-of-operations result depends on reading “comes from the method” as “would hold whatever key was chosen”. The proof now states that assumption instead of leaving it implicit.

How confident we are

What we know and don’t know

The arithmetic is certain: it is short, anyone can check it by hand, and a proof checker has verified it. What it means is far less certain. Nothing on this page can tell a property of Sanborn’s method apart from a 1-in-a-few-hundred coincidence that was noticed because someone was looking. Only more plaintext can settle that.

High: the 13 of 13 agreement, the exact odds, and every consequence of the cipher model described above.
Moderate: that the pattern is unusual. About 1 in 2,000 before allowing for the search, roughly 1 in 100 to 200 after; the allowance is an estimate.
Low: that it reflects how K4 was enciphered rather than chance.

Sources. Richard Bean, “Cryptodiagnosis of Kryptos K4”, HistoCrypt 2021 (the key equality at positions 28 and 66, and the Stehle run). Ferdinando Stehle, “help needed to break KRYPTOS”, sci.crypt, 2000. Proofs, figures and the reproduction command: formal/k4_parity on GitHub. The Stehle chance figure: scripts/crib_analysis/e_crib_34_stehle_null.py. For how we grade claims, see How we test.

What we’ve learned about K4 → · About Kryptos & how the cipher works → · How we test →