﻿# MVUEH: native-scan review and stronger short-message attacks

**The target remains unsolved.** This phase produced a source-based revised reading, successful plugboard-recovery controls, and 487 additional bounded target experiments. No MVUEH plaintext or key has been accepted.

## What improved

The original PDF contains a 3110 × 4618 embedded image of the message form. It was extracted directly, separated into red/green/blue channels, and normalized against a broad local background. The process changes pixel tones without generating replacement strokes. The original compressed scan remains the evidence; the earlier AI-edited image was excluded from transcription decisions.

The new preferred opening is `ICRVS ORMCC WQTAT`. The final indicator letter now leans toward I, giving `KCI`, while C remains an alternative. Eight body positions are marked uncertain, including a newly flagged R/L at position 43. [Detailed reading and comparisons](evidence/experiments/docs/MVUEH-native-scan-reading.md).

Two nearby NF forms were downloaded and inspected. The WNFGI duplicate has a similar upright hand and operator signature; the other form has different, strongly slanted writing. This is useful comparison material, but not proof of common authorship. The public links and targeted searches did not yield the original received No. 172 scan. A [request draft](evidence/experiments/docs/request-original-scan.md) is prepared and has not been sent.

## Attack calibration

The initial small-seed hillclimbs failed. Expanding to all disjoint two-plug seeds and using logarithmic military trigrams recovered the complete published plugboard for all six controls. An additional hybrid method first propagates the three public indicator equations, then tries one more plug and hillclimbs the remaining connections while preserving those equations.

**For this table, the correct rotor order, rings and message start were supplied.** Neither the plaintext nor plugboard was sent to the attack. These are conditional plugboard-recovery tests, not demonstrations of full unknown-key search.

| Control | Body letters | Two-plug/log attack | Indicator + one-plug attack | Four added substitutions | Seven added substitutions |
|---|---:|---|---|---|---|
| SIPVX | 94 | Recovered | Recovered | Recovered | Recovered |
| ABAHP | 81 | Recovered | Recovered | Recovered | Recovered |
| CFYZR | 72 | Recovered | Recovered | Recovered | Recovered |
| WNFGI | 59 | Recovered | Recovered | Recovered | Failed |
| GLPTL | 67 | Recovered | Recovered | Recovered | Recovered |
| MAKJH | 85 | Recovered | Recovered | Recovered | Recovered |

The errors are deterministic substitutions added to the already imperfect published ciphertexts. Recovery means the exact published plugboard ranks first, not merely that an output re-encrypts. Six hand-selected controls do not establish a success probability for MVUEH. The legacy frequency table may include material related to these controls; this is not a statistically independent held-out evaluation.

The GLPTL harness initially used the uncorrected indicator KLN. The recovered-key table explicitly corrects it to KLW and supplies start YXC. Initial GLPTL trials are retained but excluded from valid recovery rates. Later trials use the documented correction. [Recovered keys and corrections](https://cryptocellar.org/bgac/e-keys-july-1941.html).

The faster indicator-only variant, without the extra plug enumeration, recovered three of six at the correct state. It is faster but less sensitive and cannot support exclusions from unsuccessful heuristic searches. The two-plug method tries 45,176 initial boards: the empty board, 325 one-plug boards, and 44,850 two-plug boards. Its design follows the partial-plugboard approach discussed by [Ostwald and Weierud](https://cryptocellar.org/pubs/enigma-modern-breaking.pdf); the implementation and hybrid extension are part of this investigation.

### Tests with the message start withheld

Separate searches enumerate starts in fixed ascending 256-state batches, with correct order and rings supplied but no start, plugboard or plaintext clue. The evaluator stops a control run after the published key is recovered; the attack itself never receives that answer. This is a recovery benchmark, not a claim to have exhausted every start after finding a solution.

All three controls were recovered with their message starts withheld:

| Control | Starts covered before the evaluator stopped | Recovered start | Result |
|---|---:|---|---|
| CFYZR | 1,024 | BER | Exact published plugboard and observed plaintext ranked first |
| ABAHP | 8,448 | MKO | Exact published plugboard and observed plaintext ranked first |
| MAKJH | 11,776 | RHL | Exact published plugboard and observed plaintext ranked first |

The intervals start at AAA and have exclusive upper bounds recorded in `results/phase2/start-search-*.json`. Rotor order and rings were still supplied. No body crib was supplied. The searches stopped after benchmark recovery and did not exhaust all 17,576 starts or any unknown rotor/ring configuration.

## New target searches

All orders and ring triples below use the tested Enigma I stepping model with reflector B. Counts overlap; they are not distinct keys or a percentage of the global Enigma space.

| Experiment | Coverage | Result |
|---|---|---|
| Revised reading under known same-day boards | Both boards, all 60 orders, all 17,576 ring triples, both indicator readings | 4,218,240 evaluations; no accepted candidate |
| Context-crib constraints with unknown board | V–II–I, the 52 ring triples JQA–JQZ and MRA–MRZ, four cribs at all fitting offsets, both indicators, eight disputed positions retained as erasures with allowed-letter constraints | 416 runs; 204,750,000 crib/settings evaluations; zero satisfying partial boards |
| Wider ring pilot | V–II–I, the first 32 ring triples AAA–ABF, `ANROEMEINSBERTA` at all fitting offsets, both indicators and the same eight-position uncertainty set | 64 runs; 38,000,000 crib/settings evaluations; zero satisfying partial boards |
| Cable-setting hypotheses | 442 board records derived from the two same-day boards; all 17,576 ring triples at V–II–I; five transcription/indicator variants | 38,842,960 evaluations; no accepted candidate |

Total: **285,811,200 overlapping target evaluations across 487 completed manifests.** The cable hypotheses include the published boards, one removed cable, an endpoint moved to an unused socket, or a crossing of two cables. Nine and ten pairs are explicitly distinguished. This assumes the hypothesized board was used for both the indicator and body; it does not cover a cable changing during encryption.

The four new cribs are `ANROEMEINSBERTA`, `SOFORTFUNKANTWORT`, `WASCHBUSCHWISCHBUSCH`, and `WISCHBUSCHWISCHBUSCH`. Their source basis and weaknesses are recorded in [the context notes](evidence/experiments/docs/phase2-context-cribs.md). None is established target plaintext. Zero solutions exclude their conjunction with the specified settings and reading assumptions, not their occurrence under an arbitrary unknown key.

For the scoring scans, leading candidates were inspected and remain incoherent. Every retained candidate is preserved for independent review. Re-encryption verifies a candidate's arithmetic; it cannot distinguish an arbitrary key from a historical solution by itself.

## Verification and reproducibility

The existing eleven machine/constraint tests pass. The phase-two audit independently checked **5,077 candidate records** with Py-Enigma, verified the indicator for constrained searches, checked permitted plug counts, and verified input/output/source hashes. It reports **PASS**. Exact totals are in `results/phase2/audit-summary.json`. Compiler binaries can be rebuilt; archived engine sources preserve prior versions. All launched searches have finished; no background computation remains running.

The original campaign's inputs and experiment files are preserved. Phase 2 uses separate variants, manifests, source snapshots and reports. Each benchmark input contains five fields only: rotor order, rings, clear Grundstellung, encrypted indicator, and ciphertext. The plugboard and plaintext answers are confined to the harness's evaluation data.

## What to do with the remaining search

The improvement is that a useful short-message attack now passes explicit recovery controls, and the ciphertext uncertainty is better documented. The remaining difficulty is the unestablished daily key: rotor order, rings, plugboard, and some ciphertext/header characters remain uncertain for MVUEH.

The strongest evidence step remains obtaining the original received No. 172 facsimile and an independent human transcription. The all-ring V–II–I runner is ready to resume at ring index 32 (`ABG`) for the declared address crib. Only 84 ring triples have been covered for that crib (52 JQ/MR triples plus 32 AAA–ABF triples), not the unrestricted 17,576. The other three new cribs cover 52 triples each. Full searches with the deeper plugboard method are costly; throughput must be measured on representative states, including states where the indicator immediately rejects a candidate and states where it does not.

No full unknown-order/unknown-ring/unknown-plug search, reflector-C campaign, or arbitrary insertion/deletion-error search has been completed. No plaintext or key is inferred from the absence of results in these bounded experiments.
