Cryptography Worldcryptographyworld.com

Section 4 — The Pad

Destroying the page

The one-time pad's security guarantee ends the moment a used page survives.

SectionThe Pad
RegisterEntry 18 of 22
LengthShort entry
An old cipher machine resting on typed pages and handwritten notes
The one system in the register with a proof behind it, and the only one whose difficulty is entirely logistical.Photograph — collection credit

The last step is not optional

The mathematics of the one-time pad are unambiguous: a key used exactly once against a truly random page of values leaves an adversary with nothing — no crib will anchor, no frequency pattern will emerge, no algebraic shortcut exists. The guarantee is absolute. It is also entirely conditional on what happens to the page after use.

A used pad page is a liability of the purest kind. The plaintext is gone, the ciphertext is transmitted — the page itself no longer serves any purpose except to hand the entire exchange to whoever finds it. If an adversary recovers the used key material, the ciphertext they have already copied from the wire decrypts instantly and completely. The cryptographic strength of the system becomes irrelevant. Breaking the pad by mathematics is impossible; recovering a carelessly handled page requires no mathematics at all.

A telegram form filled in groups of five letters
Traffic handed to a commercial telegraph office was copied as routine, and the copies were kept.Photo: Bastian Riccardi / Pexels

This is why the destruction of pad material was treated by serious users not as housekeeping but as an operational absolute, executed immediately after encipherment or decipherment, never deferred. Intelligence services and military signals units that used one-time systems in the twentieth century developed physical destruction procedures with the same weight as the encipherment procedure itself — sometimes with more, because the mathematics handled itself but the page did not.

The materials varied. Early pads were paper; some wartime systems used flash paper or silk, chosen because both ignite cleanly and quickly, leaving no legible residue. Burning was the most common method when circumstances allowed it. Where fire was not possible — in the field, in a vehicle, in a building under observation — solubility offered an alternative. Pads printed on water-soluble paper or rice paper could be destroyed by immersion, and accounts from various Cold War-era intelligence operations describe agents carrying materials that would dissolve rapidly if contact with an adversary became imminent.

The discipline demanded is uncomfortable because it is absolute. Partial destruction is not a lesser degree of security — it is failure. A corner of a page, a fragment with a dozen values still legible, is sufficient to begin recovering traffic. The system tolerates no graduations.

Reuse is the more famous failure mode, and it is mathematically elegant in how badly it breaks the guarantee. But physical survival of used material is older, simpler, and has no cryptographic content at all — it is purely a question of whether the last step of a procedure was carried out completely, immediately, and without exception. The pad's unbreakability is a promise the mathematics keeps. Whether anyone keeps the rest is a matter of discipline, not theory.

A rotor machine with its cover off and wiring visible
The wiring inside each wheel is the machine’s only real secret, and it is identical in every machine of the series.Photo: Lech Pierchała / Pexels