﻿# MVUEH: the recovered message and the evidence for its key

Current findings as of 16 September 2026 UTC.

We have recovered a working Enigma key and an 82-letter plaintext for the German Army message identified as MVUEH, dated 10 July 1941. The message asks for a route of march, gives a location as Rosenow, and requests an immediate reply by radio. The key reproduces both the reconstructed message body and the separately recorded indicator exactly.

The evidence combines the archival source readings, connected German outside the phrase supplied to the search, agreement with the indicator, and checks using separately implemented Enigma simulators. The search is complete within its stated assumptions: all 43,016 batches and both finite plugboard families have been checked, with no unresolved search scopes. Those assumptions and the remaining historical uncertainties are described below.

## The recovered message and machine settings

| Setting | Recovered value |
|---|---|
| Rotors, left to right | II – V – III |
| Reflector / entry wheel | B / identity |
| Rings, A = 01 | H M F / 08 13 06 |
| Body windows before the first keypress | R W D |
| Plugboard | AC BE DG FH KN MO PR SU TV XZ |
| Recorded indicator | GTA / KCI |

With the windows at GTA, the indicator KCI decrypts to RWD; RWD encrypts back to KCI. The message body then begins with the windows at RWD. The five-letter identifier MVUEH is separate from that encrypted body.

The preferred 82-letter ciphertext is:

```text
ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC
```

Its exact machine output is:

```text
BTTEUMANGABEDESMARSQWEGESXBEFINDEMIQINXROSENOWROSENOWXSOFORTFUNKANTWORTXWASCHBBSCH
```

An approximate English reading is: “Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio.”

The machine output retains `BTTE` and `WASCHBBSCH`. Restoring “Bitte” or interpreting the possible signature as “Waschbusch” requires editorial judgment. Expanding Q to CH and treating X as a separator are also reading conventions; they do not change the literal output used for verification.

## Why the recovered key is convincing

Exact re-encryption establishes that the calculation is correct, but every Enigma key produces reversible output. The stronger evidence is the agreement between several constraints.

The discovery search supplied the fourteen-letter phrase `ROSENOWROSENOW`, suggested by the related, already solved SIPVX message. The other 68 plaintext characters were not imposed by that crib. Under the recovered key, they form connected German about a route of march and an immediate radio reply. The separately recorded GTA/KCI indicator also agrees with the recovered body starting position.

The result does not depend entirely on changing uncertain source letters. The published received ciphertext, preserved unchanged, is:

```text
IDEVSARMCCNQTATYEVFCDBZGGSMXWLPSYWZYTCBSWURRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJFTC
```

The same key decrypts it to:

```text
BRCEUZANGAKEDESMARSVWEGESXFEFINDEMIQINXROSTNOWROSENOWXSOFORTFUNKANTWORTXWASCHBBPCH
```

The full instruction `SOFORTFUNKANTWORT` therefore appears even in the unchanged received transcription. Separately written scalar code and Py-Enigma reproduce the preferred body and recorded indicator in both directions. These checks establish mechanical agreement; the source comparison and unforced language provide the additional evidence for the interpretation.

## The search is complete within a defined scope

The declared search assumes a standard Enigma I with three distinct rotors selected from I–V, reflector B, an identity entry wheel, exactly ten plugboard pairs, an 82-letter body, the recorded source-letter alternatives, and at least one literal occurrence of `ROSENOWROSENOW`.

| Completed search measure | Total |
|---|---:|
| Search batches | 43,016 |
| Rotor orders | 60 |
| Body-stepping classes | 107 |
| Electrical anchors per class | 17,576 |
| Viable crib placements | 38 |
| Stepping-class / electrical-anchor / crib-placement coordinates | 4,287,840,960 |
| Distinct candidate body keys retained | 97,337 |
| Distinct physical keys checked against the indicator | 14,829,646 |
| Physical keys that match the indicator | 923 |
| Unresolved search scopes or plugboard families | 0 |

The coordinate total is 60 × 107 × 17,576 × 38. A stepping class groups settings with the same rotor movement over the body; an electrical anchor specifies the starting offsets used by the search. The other 31 possible crib placements violate Enigma's rule that a letter cannot encrypt to itself for every permitted source reading. Different crib placements can describe the same physical key, so this total is not a count of distinct keys or separately brute-forced plugboards.

The twelve permitted source-letter sets, using one-based body positions, are:

```text
2:CD, 3:ENR, 6:AO, 11:NUW, 20:CX, 27:MN,
37:BT, 43:LR, 44:RS, 47:RTZ, 49:UV, 80:FY
```

They define 13,824 possible readings without insertions or deletions. All eight differences between the preferred body and the published received transcription fall within these sets. The source records preserve how the alternatives were assembled, including readings inherited from an existing transcription branch.

The constraint engine solves for ten-pair plugboards and scores their best permitted readings. The portable audit checks every emitted candidate, symbolic family, completion count and reading optimum, together with contiguous search coverage and the retained file hashes. Both finite families, containing 1,260 and 3,150 boards, are fully enumerated; none of their physical realizations passes the indicator check. The audit reports `PASS_COMPLETE_DECLARED_DOMAIN` with zero unresolved families or node caps. This is completion of the declared search, not a formal certificate excluding every possible Enigma interpretation.

## Competing keys and additional experiments

The indicator alone does not identify a unique key. Its 923 surviving physical keys represent 864 distinct body keys. Separate implementations recomputed all acceptances and rejections, and each accepted body and indicator was replayed in both directions.

For these keys, the audit numerically enumerates 12,759,552 key-and-reading combinations, including 2,628,096 that satisfy the crib. The recovered message ranks first even when every scored three-letter sequence touching the supplied crib is excluded. Nearby competitors use different plugboards and garble the surrounding instruction or other text. Numerical scoring of every reading does not mean that every text has received a human language review, and no score threshold is used to declare competing keys mathematically impossible.

The SIPVX message also appeared in the initial language-training corpus. Removing its entire logical message leaves the recovered result first in the reported fixed-text comparisons using three-, four- and five-letter sequences, including comparisons outside the crib and on the unchanged received ciphertext. These rankings support the reading without providing a calibrated probability of correctness.

Two further experiments test different aspects of the result:

- **Recovery from the unchanged received ciphertext.** A search using `SOFORTFUNKANTWORT` at positions 55–71 covers all 60 rotor orders, 107 stepping classes and 17,576 electrical anchors with arbitrary ten-pair plugboards. The engine receives no source-letter alternatives, indicator or known key. Its 1,080 batches yield 24 body candidates and 4,056 physical keys; exactly one subsequently passes GTA/KCI, and it is the recovered key. A fresh rebuild reproduces every output stream byte for byte. Because this phrase was learned from the recovered plaintext, this is a post-discovery robustness check.
- **Comparison with an independent SAT model.** A Z3 formulation checks 42 distinct machine states: seven permit solutions and 35 do not. Across the sample, all 1,314 state-and-board witnesses agree with the custom engine, including the complete 1,260-board family. Malformed-model and resource-limit controls also pass, and timeouts are never counted as proofs of impossibility. This is an independent check of a sample, not a formal proof covering every search coordinate.

Among all 923 indicator-compatible keys, only the recovered key can produce the exact seventeen-letter instruction `SOFORTFUNKANTWORT` at positions 55–71 under any permitted source reading. These ciphertext positions have no alternatives in the declared search. This is another explicitly post-discovery comparison.

## The effort and the current reproduction checks

The investigation took place over two days, 14–15 September 2026. It combined archival source reading, reconstruction of Enigma procedures, search-engine development, parallel experiments, language analysis and verification. The totals above describe the completed search and its retained evidence.

The archived logs contain measured CPU and process times for individual computations. They do not provide a complete total for human work or model reasoning, and parallel process times cannot be added together as elapsed research hours. We therefore describe the overall effort as a two-day investigation rather than attach an unsupported total-hour figure.

A fresh audit of the public downloads on 16 September checks all 28,020 files in the completion archive's inventory and verifies the retained evidence for all 43,016 scopes. It also rebuilds and runs the original winning batch, both finite-family enumerations, selected search jobs, the independent SAT sample and all 1,080 unchanged-source batches. Candidate collection, indicator filtering and reading-score checks reproduce the reported totals.

That download audit verifies every retained search record and reruns the listed experiments. It does not rerun the entire 43,016-batch numerical campaign. The archive includes instructions and code for readers who want to do so.

## The available sources and remaining uncertainties

The available source material includes the [published received transcription](https://cryptocellar.org/bgac/g-army-july-1941.html), the [outgoing NF 88/61 facsimile](https://cryptocellar.org/bgac/spruch/10071941-088-061-out-nf.pdf), and the [incoming No. 172 facsimile](https://cryptocellar.org/bgac/spruch/10071941-172-in.pdf). The incoming form records MVUEH and GTA/KCI; it is a ciphertext form, not an independently preserved plaintext. The [source update](source-update.md) documents its availability and its relationship to the source material used in the search.

Some questions remain distinct from verifying the key:

- Faint or conflicting letters need source-by-source judgment. The preferred reconstruction follows the declared alternatives; a fresh, blind transcription of the incoming facsimile would provide a useful additional comparison.
- The exact Rosenow location and the possible signatory remain uncertain. The machine calculation cannot establish a person's identity or settle the message's precise retransmission history.
- Local records and hashes preserve the search inputs and reported chronology, but they are not externally authenticated timestamps.
- The completed search does not exclude configurations with another reflector, another cable count, a different indicator procedure, a different text length, readings outside the recorded sets, or plaintext without the supplied crib.

Independent specialist review of the facsimiles, language and historical context is the most useful further assessment of those questions. The available result is a reproducible key and literal plaintext supported by the completed conditional search and the checks described here.

## How to inspect and reproduce the result

For a quick calculation check, download the [standalone key checker](MVUEH-key-verifier.zip) and follow its README. It needs Python 3.10 or later and no extra packages. To run the code that recovered the message, use the [recovery search package](MVUEH-verified-solution.zip). To inspect every declared batch, competing candidate and additional experiment, follow the [full reproduction instructions](completion-readme.md) and obtain the complete audit from the website's download section.

The following paths are inside the complete audit archive:

| Evidence to inspect | Archive location |
|---|---|
| Exact body, key and indicator | `original-discovery/verify.py`, `original-discovery/evidence.json` |
| Complete search coverage and its audit | `portable-final/clean-check/verification.json`, `coverage-audit/FINAL-REPORT.md`, `search/COMPLETION-SUMMARY.json` |
| Retained raw search records | `portable-final/batches.jsonl.gz`, `portable-final/supplements.jsonl`, `portable-final/PACKING.json` |
| Competing keys and reading comparisons | `candidate-audit/final-union/`, `candidate-audit/REPORT.md` |
| Complete finite-family enumerations | `deferred-family/REPORT.md`, `search-supplements/`, `coverage-audit/supplement-audits/` |
| Recovery from the unchanged source | `unchanged-source-recovery/REPORT.md`, `unchanged-source-recovery/reproduce.py` |
| Independent SAT sample | `sat-crosscheck/REPORT.md`, `sat-crosscheck/reproduce.py` |
| Recorded computation costs | `search/RESOURCE-COSTS.json` and the experiment reports |
| Source comparison records | `source-review/REPORT.md` and the original source audit |
| Package integrity and reproduction commands | `README.md`, `FILE-SHA256.json`, `verify_inventory.py` |

The underlying research records remain available with their original dates and experiment details. Each verification result applies to the computation and assumptions it names.
