Tapeless Rotorless On-Line, abbreviated TROL,
is a generic expression for electronic self-permuting cipher systems
for telegraphy (telex),
of which the key generator has no moving parts. TROL systems were developed
in the early 1960s by several parties and countries, as an alternative
to rotor-based cipher machines
like Enigma, Hagelin
and KL-7, and also to one-time tape 'mixers' (OTT).
TROL machines form the transition from
rotor-based to processor-based cipher machines.
TROL is also the name of a NATO-evaluation that took place in July 1962,
in which several countries submitted a design for a TROL system that
would be suitable for NATO-wide use. All submitted designs were tested
by NATO's Security and Evaluation Agency (SECAN).
Several submitted designs passed the tests, but eventually the
British BID/610 (ALVIS) was chosen, despite the fact that it
was not recommended by the evaluation committee. Apparently it was chosen
for its additional features.
As these features were not part of the initial specification,
there were protests from Germany, France and the Netherlands,
but they could not change the outcome.
Although the initial intention of NATO was to select a single device for
all telegraphic communications,
it soon became clear to the Evaluation Group that
no single equipment could fulfill all requirements. It was therefore decided to
differentiate between point-to-point and tactical use.
Several countries developed possible TROL solutions – as listed above – but
eventually only five devices were submitted: Germany (1),
the Netherlands (1), France (2) and the USA (1).
The other designs were withdrawn by the submitting
countries and are crossed out in the overview above.
The Evaluation Group consisted only of experts of the countries which had
submitted a TROL candidate. On 1 February, the recommendations of the
Evaluation Committee were presented to the Council,
as shown in the table above in the column 'Majority' [2].
Both France and the Netherlands objected and suggested an alternative
evaluation scheme, but that did not change the outcome: the German
ELCTROTEL, made by Siemens,
was by far the best device for point-to-point operation.
Nevertheless, the Council decided differently and selected the British
ALVIS (BID/610), extended with a
VENDOR (BID/700) synchroniser — most likely
a political decision.
The selection of a TROL device for tactical operation was postponed,
probably as a result of the French objections,
but was later decided in favour of the American KW-7, which
was smaller and more cost-effective than the other candidates. A major
drawback of the KW-7 is that, unlike the competition,
it does not offer Traffic Flow Security (TFS).
Procurement of both winners (ALVIS and KW-7)
started as late as 1966, and the devices were rolled out over the course
of 1967 and 1968.
France objected against the evaluation method and
suggested these alternative values.
The Netherlands objected against the evaluation method and
suggested these alternative values.
ECOLEX V is a combination of three devices:
ECOLEX IV, SIMILEX and TAROLEX.
When is a device a TROL?
In order to be categorised as a TROL, a device has to meet the
following criteria:
According to NATO (SHAPE), 'high-grade security' means that it can
resist cryptanalysis, by the most capable organisation in this field,
for 45 to 60 days [25 p.4].
TROL developments in the Netherlands
The first ideas for developing a TROL system in the Netherlands,
started circulating in 1958, probably after NATO announced its
forthcoming TROL-evaluation, which would take place in mid-1962.
At the request of the Dutch Ministry of Defense (and probably others),
three parties independently started the development of a TROL-system [23]:
CRYPTAUPHYL TNO is a Dutch state-owned laboratory for physics research and development.
At the request of the Dutch Government, TNO developed a TROL candidate
named Cryptauphyl. After an initial rejection
by the Dutch cipher authority NBV, it was improved several times, but was
not submitted to NATO and was never taken into production.
The project was cancelled in late 1962 or early 1963.
➤ More
DELFT TROL
At Delft University, Prof. Roelof Oberman
and his colleague Anton Snijders,
colloquially known as the Delft Group (Dutch: Delftse Groep),
developed another TROL-candidate in cooperation with the Dutch cipher
authority NBV. Despite its potential, it was never taken into production,
although some of its ideas may have been used in other designs.
ECOLEX V (Similex)
Philips was the only commercial party to develop a TROL candidate,
named ECOLEX V.
The idea was to develop it as an add-on device that could be used to convert
an existing Ecolex IV into a TROL. The device was submitted to NATO
in July 1962, but the bidding race was lost to the British
ALVIS (BID/610)
and the American KW-7.
➤ More
Although each of the above parties initially developed a TROL candidate
independently, a commission was later formed in an attempt to streamline
the developments and potentially combine them into a single design.
This never happened though, and each party continued its own design.
Initially, all three designs were rejected by the Dutch cipher authority
NBV, as they were all based on Linear Feedback Shift Registers (LFSR).
This shows that in 1961 even renowned knowledge institutes were not (yet)
aware of the weaknesses of linear systems. Guided by the NBV
– which was aware of these weaknesses – the systems were later upgraded
with nonlinear operations, which greatly improved
their cipher security. Eventually, only the Philips
design — Ecolex V (also known as Similex) —
was submitted for evaluation by NATO, but lost to the
British BID/610.
This didn't stop the Netherlands from further developing the TROL
concept for its own (military) use, which ultimately resulted in the
Tarolex (1967), Ecolex X (1972)
and finally Aroflex (1982). The latter was developed
for another NATO contest under the name CEROFF.
Although stricktly speaking it was an offline cipher machine,
it could also be used online, which makes it a TROL.
In France, each of the three armed forces developed its own cipher system,
in the hope that at least one of them was suitable for submission to NATO.
The following machines were developed between 1960 and 1963:
ULYSSE
This device was developed by the French Navy with help from SEA.
It apears to have a capacitor-based memory.
ULYSSE entered the NATO-competition as one of the two French submissions
(the other one being MYOSOTIS). It was later determined that the
device was cryptographically weak [24].
VIOLETTE
Violette was developed for the French Air Force by SAGEM. It was designed
to be compatible with the American KL-7 rotor-based cipher machine.
It had two modes of operation: (1) KL-7 compatible mode,
(2) National proprietary mode (more secure).
Although it did not have physical rotors, the electronic design was 'too close to rotors',
as a result of which it was rejected. The circuit was based on cold-cathode
Thyratrons, which made it heavy, bulky and indiscrete (from a TEMPEST point of view).
MYOSOTIS
On behalf of the French Army, MYOSOTIS was developed by CSF.
Its operation is based on pseudo-randomly generated alphabet substitutions [24].
It was one of the two devices submitted by France for NATO's TROL evaluation,
and was later choosen as the common machine for all French armed forces.
Eventually, only ULYSSE II and MYOSOTIS
were submitted to NATO, but according
to the French, the selection procedure was not transparent. All tests were performed
by American engineers at SECAN, and no French experts were allowed to be present.
In the end, the contest was lost to the British ALVIS (BID/610),
which (again, according to the French) was the largest and most expensive device
with the slowest performance [24].
MYOSOTIS
was eventually choosen as the national encryption machine for all
armed forces — Navy, Air Force and Army — and for use by the Foreign Ministry.
It was produced in quantity by
Thomson-CSF (now: Thales), with the telegraph control
subassembly manufactured by SAGEM as a form of compensation for its lost
VIOLETTE offering.
Although not being choosen for NATO, MYOSOTIS
received approval for NATO messages at the highest security level [24].
Although that was a small victory for France,
it didn't bring much: France left NATO in 1966, 1 whilst the Americans had full details
of the MYOSOTIS crypto-logic.
France partially left NATO in 1966, but re-joined in 2009.
Histoire de la machine Myosotis
Xavier Ameil, Jean-Pierre Vasseur and Gilles Ruggiu (ARCSI) (in French language).
Proceedings of the 7th Conference on the History of Computing and Transmission.
Aconit Grenoble, 2004. pp. 95—125.
This article contains some factual errors and omissions. It gives an incorrect
description of the KL-7 rotor machine and claims that the
other French TROL design - ULYSSE II - was never submitted to NATO, which
is contradicted by NATO documents [2]. Furthermore it does not list the
Ecolex V (submitted by
the Netherlands) as a competitor, whilst the entries
from USA,
UK
and Germany are acknowledged.