About Sophie

Cybersecurity, assurance, technology, identity, and life.

“I dare do all that may become a woman. Who dares do more is none.”

New Series: Sophie Baskerville’s History of Cybersecurity

sophie @ baskerville.net ©️1977-2026 Sophie Baskerville

017 | Genevieve Grotjan Feinstein and PURPLE


“When the Pattern Revealed the Machine”

Historical collage in purple and sepia tones showing Genevieve Grotjan Feinstein beside a reconstructed PURPLE cipher machine. Behind her are streams of ciphertext and the word “PATTERN” circled, while handwritten distribution tables in the foreground are annotated “Symmetry?” and “Possible structure”, representing the statistical relationships she identified in September 1940. A Japanese diplomatic document dated 20 September 1940 and the US Capitol appear in the background, linking the cryptanalytic breakthrough to Japanese diplomatic traffic intercepted in Washington.

Some cipher machines are broken by capturing the machine.

Some are broken by stealing the instructions, bribing an operator or discovering that someone has written the settings on a piece of paper helpfully labelled SECRET. PURPLE was broken without any of those conveniences.

Images in this article are generated by

EU AI Marker icon

EU AI Act Regulation 2024/1689

In September 1940, the United States had never seen the Japanese diplomatic cipher machine it called PURPLE. Its cryptanalysts had no captured mechanism, no wiring diagram and no obliging Japanese technician waiting to explain which lever did what. They had intercepted ciphertext, fragments of reconstructed plaintext, procedural clues, and a machine whose output appeared almost aggressively resistant to pattern.

Then Genevieve Grotjan noticed something.

She was 27 years old, a junior cryptanalyst in the US Army’s Signal Intelligence Service, and had been in government cryptology for barely a year. On 20 September 1940, while examining distribution tables built from a carefully selected group of PURPLE messages, she identified symmetries in the apparent chaos. They were the first decisive indication that the machine’s most difficult component could be reconstructed and attacked systematically. Within a week, the team was producing its first complete solutions.[2]

That is the cinematic version, and for once it is not entirely fictional.

The real achievement was slower, more collective and considerably more interesting.

A machine nobody had seen

Japan’s Foreign Ministry began introducing its Type B cipher machine in February 1939 for its most sensitive diplomatic communications with major embassies, including those in Washington, London, Berlin, Rome and Moscow. American cryptanalysts called the earlier Japanese machine system RED, so the replacement became PURPLE, because even secret intelligence organisations eventually discover colour coding.[2]

PURPLE did not work like Enigma. It divided the 26 letters into two separately enciphered groups, one containing six letters and the other twenty. Which letters belonged to which group could change through the machine’s plugboard arrangements, but the two groups passed through different internal mechanisms.

The six-letter side proved difficult but tractable. By April 1939, the Signal Intelligence Service could usually recover those letters from sufficiently long messages. That produced fragments of plaintext scattered through the text: a partial skeleton from which words and phrases might sometimes be reconstructed.[2][3]

The twenty-letter side was another matter.

The machine appeared to suppress the repetitions cryptanalysts normally hunted. Identical plaintext letters did not behave in conveniently identical ways. Repeating sequences seemed almost absent. William Friedman’s contemporary report noted that some statistical results contained fewer repetitions than would be expected from random text. The mechanism looked as though it had been designed specifically to starve analysts of the patterns they needed.

Which, to be fair, it had.

But no deterministic machine is truly without pattern. It merely has pattern that has not yet been recognised.

The clues outside the machine

PURPLE’s designers had built an ingenious cipher system. Its users then surrounded it with operational practices, duplicated messages, predictable diplomatic language, and reusable procedures. Cryptographic perfection, as usual, being issued to humans without adequate protective packaging.

RED and PURPLE remained in simultaneous use at different diplomatic posts. On some occasions, materially similar messages were sent through both systems. Japanese diplomats also transmitted English-language documents, quotations and treaty material whose likely wording could sometimes be located elsewhere. These gave the Americans cribs: plausible pieces of known plaintext that could be tested against the ciphertext.

The team reconstructed parts of about fifteen substantial PURPLE messages. Some English-language texts could be recovered almost completely after analysts located the original documents being quoted. Japanese-language material was more difficult because the Foreign Ministry used abbreviations and code-like letter groups inside the plaintext itself. Even after the encryption had been partially removed, the result could still resemble something dropped by an agitated Scrabble set. Translators and language specialists were essential.[2]

The cryptanalysts still needed comparable messages: enough material enciphered under related conditions to expose the machine’s underlying cycles.

They developed a technique they called the identification of homologs. This allowed messages sent on different days, but using the same indicator, to be converted to a common basis for comparison. Eventually they assembled a crucial set of six messages associated with indicator 59173. Two had substantially reconstructed plaintext; the others contained useful fragments.

Distribution tables were prepared showing how particular plaintext and ciphertext letters appeared across those messages.

On 20 September 1940, at about two o’clock in the afternoon, the tables finally revealed repeated and symmetrical sequences.

The machine had not stopped being complicated.

It had stopped being unknowable.

Genevieve Grotjan’s moment

Later official histories identify Genevieve Grotjan as the analyst who recognised the decisive pattern. Frank Rowlett, who led the day-to-day PURPLE effort, later recalled that she entered the adjoining room carrying her worksheets with an urgency quite unlike her normally quiet manner. Once the senior cryptanalysts inspected her result, they understood that she had found the opening they had spent months seeking.[1]

Grotjan had arrived at the Signal Intelligence Service by a route that illustrates how institutions sometimes acquire extraordinary talent accidentally.

She had graduated summa cum laude in mathematics from the University at Buffalo in 1936 and hoped to teach at university level. Suitable academic employment failed to materialise, a phenomenon not entirely unrelated to her being a young woman in the 1930s. She instead joined the Railroad Retirement Board as a statistical clerk. An unusually high score on a government mathematics examination brought her to Friedman’s attention, and in 1939 she was transferred into the deliberately vague-sounding “code section”.[5]

A year later, she was helping reverse-engineer one of the world’s most sophisticated diplomatic cipher machines.

There is an important caution about assigning credit. Friedman’s report, written only weeks after the breakthrough, explicitly described the PURPLE solution as the product of eighteen months of coordinated team effort and stated that no single person deserved the majority of the credit. Frank Rowlett and Robert Ferner directed much of the analysis; Grotjan worked alongside Albert Small and Samuel Snyder; translators, clerks, intercept operators, tabulating-machine staff and card-punch operators supplied and processed the material on which the analysis depended.

Mary Louise Prather maintained message records and found a paraphrased message that became important to the attack. Leo Rosen developed machinery to automate the decipherment. Frances Jerome managed intercept files and operated the equipment. Other specialists worked overtime to reconstruct the switch wirings once the principle had been found.

The breakthrough belongs to Grotjan.

The solution belongs to the team.

Both statements can be true, despite history’s preference for selecting one photogenic genius and moving everyone else outside the frame.[2]

Reconstructing the invisible machine

Once Grotjan’s pattern exposed the cycles governing the twenty-letter section, the team began recovering the machine’s internal logic: the sequences, starting positions and stepping relationships that produced the ciphertext.

This was black-box reverse engineering in its purest form.

The cryptanalysts knew what entered the system in some cases. They could observe what came out. From enough paired examples, they inferred the hidden transformations between them. They did not need to reproduce the Japanese machine physically; they needed to reproduce its behaviour.

Leo Rosen then designed an American functional analogue using telephone stepping switches. The resulting device could accept PURPLE ciphertext from a typewriter keyboard and print the recovered plaintext. When parts of genuine Japanese machines were captured after the war, they confirmed that the original equipment had also used telephone-style stepping switches. Rosen and his colleagues had reconstructed the essential mechanism of a machine they had never seen.[4]

That deserves to be stared at for a moment.

The Americans did not merely discover a weakness in PURPLE. From intercepted outputs, operational mistakes and mathematical regularities, they inferred enough of its architecture to build their own working equivalent.

It is difficult to find a cleaner historical ancestor for modern protocol analysis, hardware reverse engineering and attacks on proprietary systems whose designers believe secrecy of implementation constitutes a security boundary.

What PURPLE revealed, and what it did not

PURPLE decrypts gave American policymakers access to high-level Japanese diplomatic communications before and during the Second World War. They revealed negotiations, assessments, relationships among the Axis powers and reports from Japanese diplomats posted in Europe. The resulting intelligence contributed in both the Atlantic and Pacific theatres and was handled under the highly restricted MAGIC designation.[1]

PURPLE did not, however, provide a magical advance transcript of the attack on Pearl Harbor.

It was a diplomatic system, not the principal Japanese naval operational code. Its messages helped illuminate strategy and diplomatic intent, but they did not disclose the detailed fleet orders needed to identify precisely where and how Japan would strike. The NSA’s own history notes that the success against PURPLE may even have drawn cryptanalytic attention away from the naval systems that more directly reflected operational intentions. 20/20 Hindsight is a wonderful thing.[1]

That distinction matters because intelligence failures are often rewritten afterwards into stories in which all the necessary facts were already sitting in one clearly labelled folder and someone simply neglected to open it.

Reality is less accommodating. Intelligence arrives fragmented across different sources, classifications, agencies, timelines and levels of confidence. A diplomatic decrypt may reveal intention without operation. A naval intercept may reveal movement without motive. A warning can be genuine yet still not answer the questions needed to act upon it.

Breaking the cipher is not the same as understanding the world.

The cybersecurity lesson

PURPLE belongs in a history of cybersecurity because it demonstrates that a system’s observable behaviour is part of its attack surface.

The machine’s internal construction was secret. Its outputs were not. Its operators’ procedures were not. Its message formats, indicators, repeated diplomatic language and occasional duplication across systems were not.

Every time PURPLE was used, it revealed a little about itself. Most individual messages disclosed almost nothing useful. Collected across months, compared under the right conditions and combined with reconstructed plaintext, they exposed the structure of the hidden mechanism.

Modern systems repeat this mistake enthusiastically.

A proprietary authentication protocol may conceal its source code while leaking timing differences. An encrypted service may reveal message lengths and traffic patterns. A hardware device may hide its circuitry while exposing power consumption, electromagnetic emissions or fault behaviour. A machine-learning model may conceal its parameters while allowing carefully designed queries to reconstruct aspects of its training data or decision boundary.

The implementation may be hidden. The interface still talks.

PURPLE also shows why operational security cannot be separated from cryptographic design. Similar messages sent through RED and PURPLE created comparative material. Predictable diplomatic phrasing supplied cribs. Indicators and procedural regularities allowed traffic to be grouped. No single error destroyed the system. Collectively, ordinary use gave cryptanalysts the leverage required to understand it.

The strongest cipher in the world remains attached to message formats, operators, workflows, networks, deadlines and governments staffed by people who need to get the communiqué sent before their in-tray overflowed completely.

A second pattern in the noise

Grotjan’s PURPLE breakthrough was not her last major contribution.

In 1943 she was assigned to the Soviet communications problem that became the VENONA project. Soviet intelligence services had used one-time-pad material more than once, violating the essential rule that such key material must never be reused. Grotjan developed a method for recognising the reuse, helping analysts align and attack related messages. The NSA later described this as the most important single cryptanalytic breakthrough in VENONA.[1]

The connection is almost too neat.

PURPLE appeared to suppress repetition, but Grotjan found structure across related messages.

VENONA should have been protected by mathematically perfect encryption, but reused key material created relationships between messages.

In both cases, the decisive weakness was not an obviously foolish cipher. It was the existence of a relationship that should not have been visible, noticed by someone patient enough to find it.

What the artefact really is

The obvious physical artefact is the American PURPLE analogue: the remarkable machine built to imitate an unseen Japanese device.

But the more important artefact is Grotjan’s distribution table.

Rows and columns of letters. Repetitions counted. Relationships compared. Nothing glowing. No dramatic rotor clattering into place. Just evidence organised carefully enough for a hidden structure to become visible.

That makes it an unusually honest cybersecurity artefact.

Security work is often represented by machines, command centres and people looking sternly at maps. Much of the real work is closer to Grotjan’s table: collecting observations, normalising data, comparing cases, challenging assumptions and noticing that two things everyone else regarded as unrelated are behaving in suspiciously similar ways. There are some sensitive modern analogues to this approach today.

PURPLE was designed so that its patterns would disappear. Genevieve Grotjan found one anyway. The Americans had never seen the machine, but they saw what it could not help revealing.

And from that, they built another.

Purple Signature of Sophie Ada Mathison Violet Baskerville
References & Links

[1] NSA Hall of Honor biography of Genevieve Grotjan Feinstein, covering PURPLE, VENONA and her later career. (NSA)

[2] William F. Friedman’s October 1940 preliminary report, especially the technical chronology, the 20 September breakthrough and the detailed credits to the wider team. (NSA)

[3] NSA histories of RED and PURPLE and the National Cryptologic Museum’s PURPLE exhibit, for the machine’s operation, diplomatic use and reconstruction. (NSA)

[4] NSA biography of Leo Rosen, for construction of the American functional analogue. (NSA)

[5] University at Buffalo’s biographical account, useful for Grotjan’s education, recruitment and the remembered circumstances of her breakthrough.

buffalo.edu article

buffalo.edu full magazine PDF, see pp34-38